Issues
- 39
update for phpsec.owasp.org?
#120 opened by enygma - 108
confidentialString function uses hard-coded key
#108 opened by asgrim - 0
Test
#62 opened by SamanthaGroves - 5
need for isUserIdValid() in session library
#74 opened by mebjas - 12
Binding ip address with session
#84 opened by mebjas - 0
[SECURITY] phpsec user system XSS
#119 opened by AndrewCarterUK - 0
[SECURITY] phpsec/user.php - Passwords converted to lower case before hashing
#118 opened by AndrewCarterUK - 0
- 0
- 0
- 0
- 0
- 3
PROJECT NEEDS TO BE SLATED AS INACTIVE
#109 opened by cscasanovas123 - 1
mail injection prevention
#83 opened by mebjas - 3
brute force detection for time based bots
#85 opened by mebjas - 0
- 3
- 2
BasicPasswordManagement::hasOrderedCharacters does not involve string encoding
#50 opened by SvenRtbg - 5
- 1
use of bcrypt as a hashing algo
#67 opened by rash805115 - 3
Coding Convention contradicts itself.
#104 opened by hakre - 4
- 7
- 3
hasKeyboardOrderedCharacters is not localized
#26 opened by vanderaj - 2
- 4
Session expires even when user is active
#78 opened by rash805115 - 5
Last login
#72 opened by rash805115 - 5
Modification in Rand::randstr() function required
#89 opened by mebjas - 25
- 9
The "tabs" vs. "spaces" issue
#59 opened by SvenRtbg - 6
HttpRequest::URL() and HttpRequest::ChangeProtocol incorrectly use HttpRequest::ServerName()
#31 opened by SvenRtbg - 1
Trailing whitespaces issue
#90 opened by shivamdixit - 2
doubt about error handling in session library
#82 opened by mebjas - 3
Question : Session
#80 opened by paulocmguerreiro - 1
Question: Rand Library
#75 opened by paulocmguerreiro - 9
user::resetPassword() is a DoS waiting to happen
#27 opened by vanderaj - 4
user::rememberMe() review
#28 opened by vanderaj - 1
- 12
Hashing Algo and Concat of hash+dynamic salt
#66 opened by rash805115 - 11
overhead in session library?
#68 opened by mebjas - 1
Storing static salt in database
#65 opened by shivamdixit - 0
- 1
- 25
confidentialString incorrectly converts the string back to its original value.
#53 opened by SvenRtbg - 3
- 3
call-time-pass-by-reference is used
#49 opened by SvenRtbg - 9
Scanner Parser
#48 opened by abiusx - 16
- 7
- 2