BugTraq
GamePlay.co.uk XSS Jun 10 2006 12:57AM
charlie thehackersplace org (1 replies)
Re: GamePlay.co.uk XSS Jun 14 2006 01:10AM
Patrick Morris (patrick morris hp com)
On Sat, 10 Jun 2006, charlie (at) thehackersplace (dot) org [email concealed] wrote:

> The current password is not necessary for a successful password change for members of gameplay.co.uk which makes changing passwords through scripts as easy as tying your shoe lace.
> (https://shop.gameplay.co.uk/gameplay/changepassword.asp)
>
> I tried emailing these clowns about their silly flaws, but I had no joy.

If you are not logged in, that URL takes you to a login page, where you
*do* need to enter a correct username and password.

I'm not sure what happens if you've already logged in with a valid
account.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus