Mantis - Quercus
Viewing Issue Advanced Details
1252 major always 07-15-06 19:23 07-17-06 16:51
ajiaojr  
ferg  
normal  
closed 3.0.19  
fixed  
none    
none 3.0.20  
0001252: mantis bt not checking user passwords when they login.
I did a fresh installation of mantis. As long as I specify the username correctly, I am able to login, what I type in the password field doesn't matter.

A fresh installation on apache+mod_php however do require one to specify the correct password.

This problem also exist on http://bugs.caucho.com [^] and IMO is a security flaw.

There are no notes attached to this issue.