seventoes
on Jul 11. 2006. 1:03 am

Ive been using activeCollab for a couple of days, and when my mysql server went out temporarilly, this is what i saw... This is a HUGE security risk. NEVER should a script show any passwords for anything. Please fix this A.S.A.P.!
Staff
Ilija Studen
on Jul 11. 2006. 1:09 am
I had the same problem when we got dugg. Script was in the debug mode and everyone got database connection params on the plate as soon as database server failed to respond to all those requests.
I though it was fixed but apparently I made the fix only for the live installation, not in the code. Thanks for noticing this.
Fix is included in
0.6 community preview.
activeCollab team member |
LinkedIn