Web pages can only set cookies for the second (or higher) domain to which they belong.
This means that secure.example.com can read and set cookies for secure.example.com or .example.com , the latter of which can also be read and set using www.example.com
Last note: if a safe flag is set in the cookie, it can only be read and set via the https connection.
Powerlord
source share