Menu

#1 Social Bookmarking password Vulnerability

open
nobody
None
5
2007-05-22
2007-05-22
bobbocanfly
No

There is a potential vulnerability in the way that the passwords for Magnolia and del.icio.us in the Linkwalla system. They are stored in plaintext within a php document with no HTML frontend. This means that malicious users could type http://www.<installationsite>.com/lwFunctions.php. (www.<installationsite>.com) Their browser then should attempt to download the file displaying the password in plaintext to the malicious user. This can also be done using programs like NetTransport which downloads plain files from web servers.

Discussion


Log in to post a comment.