note 73819 deleted from function.setcookie by danbrown
| From: | danbrown@php.net | Date: | Sun, 17 May 2009 17:52:12 +0000 |
| Subject: | note 73819 deleted from function.setcookie by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-155034@lists.php.net to get a copy of this message | ||
Note Submitter: mbowie at NOSPAM dot buzmo dot com
----
It would seem that set_cookie will still set a cookie via HTTP, even if the secure parameter is
true.
So even if your site uses HTTPS/SSL to communicate sensitive data, if the initial cookie was set by
set_cookie via HTTP, an attacker listening on the wire could easily spoof a visitor's cookie
and gain access to their session.
See: http://bugs.php.net/bug.php?id=40778