|
Oempro has a flaw that may allow an attacker to more easily access sensitive cookies. The PHPSESSID session cookie is set by the application without the 'secure' flag. Without this flag, a web browser may transmit the cookie in cleartext (i.e., unencrypted) potentially allowing it to be intercepted.
|