The change [2] is not doing, what the poster suggests, but it avoids many threads concerning stealing and manipulating session_ids. The session_id management in OpenACS is quite tricky and differs from many other framework, since it involves the interplay with other cookies as well. So, at least some attacks on session_ids from other frameworks don't necessarily apply as well on OpenACS.
OpenACS 5.9.0 fixes many more other attack vectors related with cross site scripting. The forthcoming OpenACS 5.9.1 addresses more injection attacks (both cross site scripting and SQL injection) identified with newer scanning and provides as well framework support for CSRF attacks (cross site request forgery)