Whoooo, damn....thank god for RSS. Yesterday Danny Douglas posted a serious security issue concerning Blogengine.NET where people could access my website credentials by accessing the JavaScript HttpHandler via a browser and requesting my
users.xml.
View my security hole here:
...
[More]