(July 13, 2012 at 3:27 pm)Tiberius Wrote: If that wasn't bad enough, the passwords were being stored in the database in plaintext.
This part is criminally stupid.
Users will be users, and bad passwords are for now a fact of life.
That the service is vulnerable to a SQL injection with passwords stored in plain text is so far beyond stupid, when those responsible should be expected to know better. Are they stuck in 1979 or what?