Logging into the Triton management interface ( W2k8-R2, with websense: 7.7.3) sets a WS_SESSION cookie.
This cookie is not protected by a httponly flag thereby raising the impact of a possible XSS vulnerability.
RFE: set the HTTPonly flag on session cookie.
Internal reference: M09
↧
NO httponly flag set on the WS_SESSION cookie upon triton login (version 7.7.3 windows)
↧