Cross-Site Scripting (XSS)
Description
Going Beyond 'Document.Cookie'
Why HttpOnly Isn't Enough
Testing / Payload Creation
Last updated
Last updated
# This is the flag we are talking about
Set-Cookie: SESSIONID=[token]; HttpOnly