Needs work
Project:
Secure Pages Hijack Prevention
Version:
6.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
23 Dec 2010 at 16:02 UTC
Updated:
1 Jan 2011 at 06:17 UTC
Jump to comment: Most recent file
Comments
Comment #1
damienmckennaTry this.
Comment #2
grendzy commentedCan you explain how this might occur? The secure flag on the cookie would normally prevent this. Are there any known conditions where this flag isn't honored?
Comment #3
damienmckennaIt's a pretty far reaching case and would probably have to have other things involved (XSS, maybe) but isn't it worth the few extra lines of code just to close off a possible gap, however probable?