It does not. It is the difference between an exploit that yields a root password and one that yields a shell at uid=0.
HttpOnly is almost totally cosmetic.
HttpOnly is almost totally cosmetic.
I'm probably coming over as too offensive, but you really really don't seem to know what you are even talking about. You are wrong wrong wrong.
http://blog.portswigger.net/2016/05/web-storage-lesser-evil-...