Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Unable to impersonate another user although having its cookie Jul 01 2009 02:30PM
Irene Abezgauz (irene abezgauz gmail com)
Juan,

A few questions to direct this -

1. are there any parameters in the request itself that are not the
cookie and can be suspected as client/session identifiers?  (either in
the body of a POST or as part of the URL in a GET)?
2. are you trying to execute a similar request? is there a chance you...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus