|
Well, right off the bat I can say that there are a lot of XSS exploits present there so you would have a lot of people having their accounts stolen. (I also thought that there was SQL injection points through the AJAX but apparently all those included JS files are useless, and access to the file executeDB() calls is denied.) If you patch it all up you'd be safe probably.
|