Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
By exploiting the vulnerability, "malicious users can fool other users' Web clients...which allows them to do things such as stealing that client/server's cookies," Elias Levy, Bugtraq's moderator and the chief technology officer of SecurityFocus.com, wrote in an advisory. Calling the vulnerability a "common flaw," Levy blamed the problem in part on "the lack of good practices by programmers of Web-based applications."
The link for this article located at ZDNet is no longer available.