Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-1971

Deleting or putting "false" in the validation cookie bypasses cookie validation

    XMLWordPrintable

Details

    Description

      The validation cookie can be used to bind a cookie to an IP. Stealing the username and password cookies can bypass the IP bind if the validation cookie is assigned a value of "false" or is completely deleted.

      Attachments

        Activity

          People

            sdumitriu Sergiu Dumitriu
            sdumitriu Sergiu Dumitriu
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: