The big lie of computer security is that security improves by imposing complex passwords on users. In real life, people write down anything they can't remember. Security is increased by designing for the way humans actually behave. -Jakob Nielsen
Points: 25 Description: Nines9 and evinyatar found an XSS/CSRF vulnerability in realistic 11 that allowed them to edit user profiles, send PMs, submit articles and bug reports as members.
# 2
Points: 100 Description: evinyatar and Nines9 found an SQL injection in Realistic 8, which allowed them to inject arbitrary SQL code.
HackThisSite is the collective work of the HackThisSite staff, licensed under a CC BY-NC license.
We ask that you inform us upon sharing or distributing.