Reuben Wells wrote:
> Following the announcement the Logitech acquired SlimDevices and the
> emails to its customers, it is nice to see that the new company takes
> its customers security so seriously.
>
> Signing up to their news letter returns a link that looks like this:
>
> http://www.slimdevices.com/subscribe/?p=preferences&uid=74xxx
>
> Simply changing the "uid" in the query parameter above enables you to
> view any of SlimDevices customers email addresses.
>
> This is shockingly poor.
>   

I agree, fix this ASAP guys!
I suppose we're lucky they haven't got our CC numbers in there.

P.

_______________________________________________
discuss mailing list
[email protected]
http://lists.slimdevices.com/lists/listinfo/discuss

Reply via email to