Is it just me or is that behavior idiotic? I've seen this bug in _multiple_ scripts I've audited. For that reason, I feel much less safe signing up for cookies on websites that I haven't audited myself for this problem. Since it is a script tag, that could open many a hole later down the line that I haven't mentioned as well. It's just another reason to disable javascript and never use cookies for authentication.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html