Comment Re:This issue is way overblown. FUD (Score 3, Informative) 225
Nope, it affects https as well. Furthermore, it does not require remote web management since the attack can be carried out via CSRF.
Thus spake the master programmer: "When a program is being tested, it is too late to make design changes." -- Geoffrey James, "The Tao of Programming"