Page 1 of 1

Login - Password - Bypassable

Posted: October 1st, 2008, 6:39 pm
by alexaa
I noticed today that, if you open sabnzbd (in Windows), when prompted for a password, you can close the window and navigate to sab's regular address (http://localhost:8080/sabnzbd/) and you are logged in; bypassing any password requirements.

I thought I would mention this.

Re: Login - Password - Bypassable

Posted: October 1st, 2008, 6:52 pm
by switch
You probably have a cached copy/still valid cookie. It is impossible to bypass the login in the manner you describe.