Microsoft IIS 4.0/5.0 Session ID...

- AV AC AU C I A
发布: 2000-10-23
修订: 2025-04-13

Under certain circumstances, Microsoft IIS will transmit the plaintext contents of Session ID Cookies that should be marked as secure. A website may require state information so that it can distinguish one user over another, especially if it undergoes a great deal of traffic load. This is especially prevalent in the case of e-commerce sites in order to keep track of an individuals shopping order, etc. as they browse from page to page. Session ID Cookies may be used as a method to acquire state information. It maintains the identity of a user as they browse a site. When a user initiates a SSL secured web session, Session ID Cookies should be marked as secure from there on (see RFC 2109 for reference: http://www.ietf.org/rfc/rfc2109.txt). This is not the case if the user visits an ASP page hosted on IIS. In the event that a user views an ASP document during a secure web session, the Session ID Cookie would then be marked as insecure. Once the user were to visit a non-secure portion...

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息