Discussions
ScanAlert Vulnerability - Potential Sensitive Persistent Cookie Sent Over a Non-Encry
NS can you please verify the validity of this vulnerability Posted Yesterday:
Name: Potential Sensitive Persistent Cookie Sent Over a Non-Encrypted (SSL) Channel
Category HTTP - Web Application
Severity Medium High In PCI
Impact Information Disclosure
Fix Difficulty Medium
Vulnerability Detail
Device www.deiequipment.com (63.209.28.41, 65.175.38.98, 66.216.107.94)
Vulnerability Potential Sensitive Persistent Cookie Sent Over a Non-Encrypted (SSL) Channel
Port 80/tcp
Scan Date 11-OCT-2008 00:32
Other
Path: // --> Sensitive Info on Insecure Channel (http) : NLShopperId=0UNyLQ8TAeJohUrW; Domain=.deiequipment.com; Expires=Sat, 18-Oct-2008 06:08:44 GMT; Path=/
Other
Path: // --> Sensitive Info on Insecure Channel (http) : NLVisitorId=0UNyLY_wAI9KigW7; Domain=.deiequipment.com; Expires=Fri, 02-Oct-2009 06:08:44 GMT; Path=/