Bug#473571: plone3: CVE-2008-139[3-6] multiple vulnerabilities
Florian Weimer
fw at deneb.enyo.de
Sat Apr 5 11:54:19 UTC 2008
* Nico Golde:
> While I agree that the cookie issues and the session id
> issue is not of an high impact I still think that at least
> the CSRF issue should be fixed cause the exploit scenario
> has a certain real life importance.
The __ac cookie issue is significant as well if the secure flag is not
set on the cookie even if login happens over HTTPS.
More information about the pkg-zope-developers
mailing list