CVE
- Id
- 36176
- CVE No.
- CVE-2008-6059
- Status
- Candidate
- Description
- xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.
- Phase
- Assigned (20090204)
- Votes
- None (candidate not yet proposed)
- Comments