<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>Horde Mail Insecure Cookie Sanitization over HTTPS</title> 
  <pubDate>Fri, 10 Apr 2026 05:02:31 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/7904</link> 
  <atom:link rel="self" type="application/rss+xml" title="Horde Mail Insecure Cookie Sanitization over HTTPS" href="https://bugs.horde.org/ticket/7904/rss" /> 
  <description>Horde Mail Insecure Cookie Sanitization over HTTPS</description> 
 
   
   
  <item> 
   <title>It is possible to send a cookies over HTTP even when HTTPS i</title> 
   <description>It is possible to send a cookies over HTTP even when HTTPS is implemented during insecure state of cookie. The parameters are not properly structured in set cookie parameter. On security basis secure parameter should be applied in the cookie arguments to prevent the transference of cookies over HTTP. 



This can be possible to Surf Jacking attacks.







</description> 
   <pubDate>Tue, 27 Jan 2009 19:02:07 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/7904#t52008</link> 
  </item> 
   
  <item> 
   <title>Please keep discussion in one ticket (#7903)</title> 
   <description>Please keep discussion in one ticket (#7903)</description> 
   <pubDate>Tue, 27 Jan 2009 19:17:05 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/7904#t52010</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
