Bug#473571: plone3: CVE-2008-139[3-6] multiple vulnerabilities

Florian Weimer fw at deneb.enyo.de
Sat Apr 5 11:54:19 UTC 2008


* Nico Golde:

> While I agree that the cookie issues and the session id 
> issue is not of an high impact I still think that at least 
> the CSRF issue should be fixed cause the exploit scenario 
> has a certain real life importance.

The __ac cookie issue is significant as well if the secure flag is not
set on the cookie even if login happens over HTTPS.





More information about the pkg-zope-developers mailing list