View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 07844 | Bug reports | Security | public | 2013-05-16 14:27 | 2013-06-09 16:43 |
| Reporter | aesteban | Assigned To | c_schmitz | ||
| Priority | normal | Severity | partial_block | ||
| Status | closed | Resolution | fixed | ||
| Product Version | 2.05 RC | ||||
| Fixed in Version | 2.00+ | ||||
| Summary | 07844: PHPSESSID cookie is not httponly | ||||
| Description | In order to mitigate XSS attacks, PHPSESSID should have the "httponly" attribute | ||||
| Steps To Reproduce | 1.- Login to application | ||||
| Tags | No tags attached. | ||||
| Bug heat | 252 | ||||
| Complete LimeSurvey version number (& build) | 130420 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | |||||
| Database type & version | Mysql 5.1 | ||||
| Server OS (if known) | RedHat Enterprise Linux | ||||
| Webserver software & version (if known) | Apache 2.2 | ||||
| PHP Version | 5.3.3 | ||||
|
Fix committed to master branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=12440 |
|
|
New version 2.00+ Build 130526 released |
|
|
Fix committed to 2.05 branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=12540 |
|
|
LimeSurvey: master 8ef1a527 2013-05-17 16:11 Details Diff |
Fixed issue 07844: PHPSESSID cookie is not httponly |
Affected Issues 07844 |
|
| mod - application/core/LSYii_Application.php | Diff File | ||
|
LimeSurvey: 2.05 6add94aa 2013-05-17 16:11 Details Diff |
Fixed issue 07844: PHPSESSID cookie is not httponly |
Affected Issues 07844 |
|
| mod - application/core/LSYii_Application.php | Diff File | ||
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2013-05-16 14:27 | aesteban | New Issue | |
| 2013-05-17 16:09 | c_schmitz | Assigned To | => c_schmitz |
| 2013-05-17 16:09 | c_schmitz | Status | new => assigned |
| 2013-05-17 16:11 | c_schmitz | Changeset attached | => LimeSurvey master 8ef1a527 |
| 2013-05-17 16:11 | c_schmitz | Note Added: 25296 | |
| 2013-05-17 16:11 | c_schmitz | Resolution | open => fixed |
| 2013-05-17 16:12 | c_schmitz | Status | assigned => resolved |
| 2013-05-17 16:12 | c_schmitz | Fixed in Version | => 2.00+ |
| 2013-05-26 21:06 | c_schmitz | Note Added: 25377 | |
| 2013-05-26 21:06 | c_schmitz | Status | resolved => closed |
| 2013-06-09 16:43 | c_schmitz | Changeset attached | => LimeSurvey 2.05 6add94aa |
| 2013-06-09 16:43 | c_schmitz | Note Added: 25486 |