Support A2Billing :

provided by Star2Billing S.L.

Support A2Billing :
It is currently Tue Apr 16, 2024 4:23 am
Hosted Voice Broadcast


All times are UTC




Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: Dangerous BUG
PostPosted: Mon May 28, 2012 4:17 pm 
Offline

Joined: Tue Jun 22, 2010 8:37 pm
Posts: 152
Hi all,

in the customer panel if you left empty the user field, the system returns a window showing the password :

You must enter an user and a password!***REALPASSWORD"


Top
 Profile  
 
 Post subject: Re: Dangerous BUG
PostPosted: Mon May 28, 2012 8:45 pm 
Offline

Joined: Mon Mar 02, 2009 8:56 pm
Posts: 271
What version is this on?


Top
 Profile  
 
 Post subject: Re: Dangerous BUG
PostPosted: Tue May 29, 2012 5:47 am 
Offline

Joined: Tue Jun 22, 2010 8:37 pm
Posts: 152
1.9.4


Top
 Profile  
 
 Post subject: Re: Dangerous BUG
PostPosted: Tue May 29, 2012 7:19 am 
Offline

Joined: Mon Mar 02, 2009 8:56 pm
Posts: 271
Confirmed. I see it in 1.9.2 also.

If you leave the username blank, but enter a password, the password is echoed back to the screen in plain text in the popup box.


Top
 Profile  
 
 Post subject: Re: Dangerous BUG
PostPosted: Tue May 29, 2012 1:37 pm 
Offline

Joined: Mon Jan 08, 2007 6:56 pm
Posts: 345
It echoes back what was typed, not something from the database, unusual though.


Top
 Profile  
 
 Post subject: Re: Dangerous BUG
PostPosted: Thu May 31, 2012 3:38 pm 
Offline

Joined: Tue Mar 06, 2012 8:47 pm
Posts: 1
Change /customer/templates/default/index.tpl line 25 from
Code:
         alert("You must enter an user and a password!" + document.form.pr_password.value);

to
Code:
         alert("You must enter an user and a password!");


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 
Hosted Voice Broadcast


All times are UTC


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group