[pmwiki-users] PmWIki AuthUser passwords stored in clear in PHPsession files

Christophe David pmwiki at christophedavid.org
Wed Oct 10 11:59:46 CDT 2007


> which temporary file contains the password ?

The path for PHP session files is defined  by "session.save_path" in
php.ini. (phpinfo() should give you the settings on your system.)

Details on http://www.php.net/session .

The files are plain text with all variables stored in clear.

Thank you for your help.

Christophe



More information about the pmwiki-users mailing list