here's a post i made yesterday to SF regarding whatpulse and one of it's profile features. I figured i would post it here seing as many of us use whatpulse and it is only fair to demonstrate that your account and anything associated with it is at risk.
[url=\"http://securityfocus.com/archive/1/404534/30/0/threaded\"]http://securityfocus.com/archive/1/404534/30/0/threaded[/url]
Whatpulse vulnerability can lead to account hijack
Moderators: Moderator, Global Moderator
-
Rift
Whatpulse vulnerability can lead to account hijack
btw this has already been reported to wasted, which is why i put it on SF, seeing as nothing was done to fix the problem. his phpmail may have failed when i sent the message but i doubt it.