Menu

#2 session vulnerability

open
Core (2)
5
2015-02-22
2007-06-07
Anonymous
No

code don't distroy the sessions so if you c/p your link to another user , attacker can log in to your account.

Discussion

  • LuckyLuke

    LuckyLuke - 2007-07-13

    Logged In: YES
    user_id=1300508
    Originator: NO

    Well, I thought I had an IP check, but I'm going to look into it.

     
  • LuckyLuke

    LuckyLuke - 2007-07-13
    • assigned_to: nobody --> luckyphp
     

Log in to post a comment.

MongoDB Logo MongoDB