漏洞类别:Web Application
漏洞等级:
漏洞信息
Session cookie set over Non-HTTPS connection
漏洞危害
Session cookie set over Non-HTTPS connection can lead to a Man in the Middle attack and cookie data can be stolen. Cookie values can be sniffed by an attacker. This later can be used to impersonate the authenticated user and gain unauthorized access.
解决方案
The general recommendation is to set the Session cookie over HTTPS (secure connection)
0day
文章评论