Jump to content

Testers wanted


apw

Recommended Posts

Im looking for testers to give me feedback on my social-community website. The source used is gpl  however ive been working to fix bugs, clean-up code, add new features as well as give the site a more personal touch.  Please tryout everything and either post comments and suggestions here or on the built-in forums om website.  Thanks in advance.

 

http://social.lmninfo.com

Link to comment
Share on other sites

Input Type Password Autocomplete Enabled

Password type input named pass from unnamed form with action has autocomplete enabled. An attacker with local access could obtain the cleartext password from the browser cache.

The impact of this vulnerability

Possible sensitive information disclosure

How to fix this vulnerability

The password autocomplete should be disabled in sensitive applications. To disable autocomplete, you may use a code similar to: < INPUT TYPE="password" AUTOCOMPLETE="off" >

Link to comment
Share on other sites

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.