WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/7458.php | vdb entry |
http://www.securityfocus.com/archive/1/223799 | mailing list |