
Its not just this, its everything.
At one point I found their image loader just let me load any file on their server something like <img src="imageloader.asp?path=c:\inetpub\somefolder\some.jpg" /> which was easily replaced with any file on the server in order to stream it.
When I discussed it with their security team they changed it to something like <img src="imageloader.asp?path=HKJSHD*IY#(#:DJGT..." /> but every image still starts with the same prefix leading me to believe that is the representation of c:\ etc in whatever lame homegrown encryption method they tried to use.
Its scary that they are in the cloud business storing sensitive information.
me and jill used to refer to the Artvoice horoscopes as boroscopes and I totally thought that was so random that you also did that, but alas you are talking about a tool.