View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
07844 | Bug reports | Security | public | 2013-05-16 14:27 | 2013-06-09 16:43 |
Reporter | aesteban | Assigned To | c_schmitz | ||
Priority | normal | Severity | partial_block | ||
Status | closed | Resolution | fixed | ||
Product Version | 2.05 RC | ||||
Fixed in Version | 2.00+ | ||||
Summary | 07844: PHPSESSID cookie is not httponly | ||||
Description | In order to mitigate XSS attacks, PHPSESSID should have the "httponly" attribute | ||||
Steps To Reproduce | 1.- Login to application | ||||
Tags | No tags attached. | ||||
Bug heat | 252 | ||||
Complete LimeSurvey version number (& build) | 130420 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | Mysql 5.1 | ||||
Server OS (if known) | RedHat Enterprise Linux | ||||
Webserver software & version (if known) | Apache 2.2 | ||||
PHP Version | 5.3.3 | ||||
Fix committed to master branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=12440 |
|
New version 2.00+ Build 130526 released |
|
Fix committed to 2.05 branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=12540 |
|
LimeSurvey: master 8ef1a527 2013-05-17 16:11 Details Diff |
Fixed issue 07844: PHPSESSID cookie is not httponly |
Affected Issues 07844 |
|
mod - application/core/LSYii_Application.php | Diff File | ||
LimeSurvey: 2.05 6add94aa 2013-05-17 16:11 Details Diff |
Fixed issue 07844: PHPSESSID cookie is not httponly |
Affected Issues 07844 |
|
mod - application/core/LSYii_Application.php | Diff File |
Date Modified | Username | Field | Change |
---|---|---|---|
2013-05-16 14:27 | aesteban | New Issue | |
2013-05-17 16:09 | c_schmitz | Assigned To | => c_schmitz |
2013-05-17 16:09 | c_schmitz | Status | new => assigned |
2013-05-17 16:11 | c_schmitz | Changeset attached | => LimeSurvey master 8ef1a527 |
2013-05-17 16:11 | c_schmitz | Note Added: 25296 | |
2013-05-17 16:11 | c_schmitz | Resolution | open => fixed |
2013-05-17 16:12 | c_schmitz | Status | assigned => resolved |
2013-05-17 16:12 | c_schmitz | Fixed in Version | => 2.00+ |
2013-05-26 21:06 | c_schmitz | Note Added: 25377 | |
2013-05-26 21:06 | c_schmitz | Status | resolved => closed |
2013-06-09 16:43 | c_schmitz | Changeset attached | => LimeSurvey 2.05 6add94aa |
2013-06-09 16:43 | c_schmitz | Note Added: 25486 |