This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Astaro's forum stores cleartext in cookies

This forum's software stores your password in cleartext in the "ubber..." cookie on your PC until you log out. 

See http://online.securityfocus.com/archive/1/164583 
and http://online.securityfocus.com/archive/1/164739 

If your browser is vulnerable to cross-site scripting (e.g. Bugtraq 3829) your password can be acquired. 

So it is highly advisable to use a password not used elsewhere - and to log out of the web application (thus clearing the cookie).


This thread was automatically locked due to age.