Your login form posts to HTTPS, but you blew it when you loaded it over HTTP
1–2 of 2 posts
Re: Your login form posts to HTTPS, but you blew it when you loaded it over HTTP
#2XSS. This is a side-effect of XSS. If you can not insert your script into the users browser you can't do anything. And if you are able to XSS you can do more than just scrap the password.