Risks: Hackers can use javascript code to steal user cookies.
Prevention: Requirements set the property "HTTP Only" for the session cookie. Because if the Session cookies are not set property "HTTP Only". We can configure the Web server side.
đang được dịch, vui lòng đợi..