Re: Serious security bug?

2001-06-05 Thread Tonu Samuel
On Mon, 4 Jun 2001 [EMAIL PROTECTED] wrote: > >Description: > User able to (accidentally!!) change/reset their own password despite not having >*any* access to the mysql database > > >How-To-Repeat > There's the trick. We can't reproduce but this happened twice. However the >setup of our

Serious security bug?

2001-06-05 Thread jboyd
>Description: User able to (accidentally!!) change/reset their own password despite not having *any* access to the mysql database >How-To-Repeat There's the trick. We can't reproduce but this happened twice. However the setup of our (very recent) mysql installation is so simple that it'