4 ms·
Yup, the cookie isn't limited to your path. What's even worse, when logged in you can edit any page: http://deadsimple.me/foobar/?edit http://deadsimple.me/foo
by ElbertF 15y ago
Yup, the cookie isn't limited to your path. What's even worse, when logged in you can edit any page:
http://deadsimple.me/foobar/?edit http://deadsimple.me/foobar/?edit
- sweis 15y agoWell, that makes the XSS vulnerability kind of moot.
- corruptnetwork 15y agoWell, you can edit pages which are NOT password protected from the owner. That's fine.
- sweis 15y agoI tried to password-protect the page in question. It may not be working properly.
- corruptnetwork 15y agoAlright, issue should be solved now. Try yourself! Thanks.