Web Server HttpOnly Cookies Not In Use
Medium Nessus Network Monitor Plugin ID 5799
SynopsisThe remote server does not adequately protect data stored with cookies
DescriptionBased on the HTTP 'Cookie' header, PVS has determined that the remote server is not using the 'HttpOnly' cookie setting. By not using this setting, client side script can access the cookie. This can allow attackers to access cookies with potentially confidential data.
SolutionConfigure your web server or application to use the 'HttpOnly' tag.