Hack Facebook with Web Based Exploit
If you know anything about programming websites you will hear about "Forgot your password" service has to directly contact with the databases in order to send requests to retrieve the forgotten information for you, basically what that means if you ask the database for the login information with the right "code", it will send you back that information.
For security reasons, the databases are programmed to verify the account your requesting is actually yours and not someone else so they need some types of authentication or verification.

