Date:
20 March 2006
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Weak Password Recovery Validation
A UK Security Consulting firm reports that 54 UK sites that it has surveyed have flaws in the "forgotten password" feature.
References: