cve/2014/CVE-2014-3852.md
2024-05-26 14:27:05 +02:00

850 B

CVE-2014-3852

Description

Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

POC

Reference

Github