duanqian6982 2015-03-19 17:22
浏览 165

Php Web服务器通用Cookie注入

Got a website where a security scan for PCI compliance has comeback with a fail for the following:

Web Server Generic Cookie Injection

Impact The remote host is running a web server that fails to adequately sanitize request strings of malicious JavaScript. By leveraging this issue, an attacker may be able to inject arbitrary cookies. Depending on the structure of the web application, it may be possible to launch a 'session fixation' attack using this mechanism. Please note that : - SecurityMetrics did not check if the session fixation attack is feasible. - This is not the only vector of session fixation. See also : http://en.wikipedia.org/wiki/Session_fixation http://www.owasp.org/index.php/Session_Fixation

I haven't been able to find much information about this error and gone round in circles about it. I'm assuming it's an cakephp issue.

Cheers

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 有人能看一下我宿舍管理系统的报修功能该怎么改啊?链表那里总是越界
    • ¥15 cs loadimage运行不了,easyx也下了,没有用
    • ¥15 r包runway详细安装教程
    • ¥15 Html中读取Json文件中数据并制作表格
    • ¥15 谁有RH342练习环境
    • ¥15 STM32F407 DMA中断问题
    • ¥15 uniapp连接阿里云无法发布消息和订阅
    • ¥25 麦当劳点餐系统代码纠错
    • ¥15 轮班监督委员会问题。
    • ¥20 关于变压器的具体案例分析