The confirmPassword() JavaScript function in changepassword.asp fails to encode the user ID and password parameters and will, therefore, fail if, for example, either (or both) contains an ampersand character.
Log in to post a comment.