Follow-up Comment #1, sr #107282 (project administration): Admins, what do I have to do to get you to take this seriously? You're currently trusting every site you visit while logged into Savannah not to take over your session and wreak havoc on the site. Should I put up an attack page that publicly displays the session cookies of its victims?
_______________________________________________________ Reply to this item at: <http://savannah.gnu.org/support/?107282> _______________________________________________ Message sent via/by Savannah http://savannah.gnu.org/