"#cross-site scripting" #cookie #security #http-only