Social Bookmarking password Vulnerability
Add a simple link blog to your website - with no database.
Brought to you by:
zenkenobi
There is a potential vulnerability in the way that the passwords for Magnolia and del.icio.us in the Linkwalla system. They are stored in plaintext within a php document with no HTML frontend. This means that malicious users could type http://www.<installationsite>.com/lwFunctions.php. (www.<installationsite>.com) Their browser then should attempt to download the file displaying the password in plaintext to the malicious user. This can also be done using programs like NetTransport which downloads plain files from web servers.