Hi vBulletin developers,
I am a security researcher at University of Virginia. I have been looking into the HTTP-only feature deployment issue. I have noticed that all sites powered by vBulletin 3.6 or better use HTTP-only cookie for security purposes. I have also observed one sites using vBulletin 3.0 which does not use HTTP-only cookie. vBulletin is the only web framework we have found to use HTTP-only cookie currently(other frameworks are open-source ones). Since we do not have access to source code and documentation, could I ask if HTTP-only is a default feature in newest vBulletin? If yes, since when did vBulletin apply HTTP-only feature?
Thank you so much!
Best regards.
__DEFINE_LIKE_SHARE__
|