Comment 20 for bug 44062

Revision history for this message
In , Darin-moz (darin-moz) wrote :

Christian:

The point is that the attacker can use this mechanism to affect the user's
interaction with the targeted site. This exploit depends on the attacker
leveraging the way in which cookies are used by a site. Imagine simple cases
where this could be used to change the contents of a virtual shopping cart or
something like that. You can imagine much worse... it all depends on how a site
uses cookies.