[Tickets #555] NEW: Login tricks

bugs at bugs.horde.org bugs at bugs.horde.org
Thu Sep 9 10:34:16 PDT 2004


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/?id=555
-----------------------------------------------------------------------
 Ticket     | 555
 Created By | aromanov at eerc.kiev.ua
 Summary    | Login tricks
 Queue      | IMP
 Version    | RELENG_3
 State      | Unconfirmed
 Priority   | 2. Medium
 Type       | Bug
 Owners     | 
-----------------------------------------------------------------------


aromanov at eerc.kiev.ua (2004-09-09 10:34) wrote:

Dear developers,

To simplify login procedure I saved the login page, inserted my login and
password data into html source. Now I need just to click the button without
typing it every time. When I tried to use the same modified login page for
another account simply copying the file and changing the login and password
data the strange thing occurred. Both accounts, then activated from the
copied login pages, can have access to each other's mail. Probably this is
due to the same identifier assigned to 'Horde2' input value that is used in
both files. Although this is not a critical error, it potentially might be
used for unauthorized access.

Thank you for consideration.
Alexander Romanov




More information about the bugs mailing list