it is possible to test if the session token is exposed to this vulnerability and try to create a replay session attack. ???<br><br> ???[[ Session Riding AoC|4.5.4 Session Riding ]]<br> ???Session Riding descibes a way to force an unknowing user to execute unwanted actions on a web application in which he is currently authenticated.<br> ???[[ HTTP Exploit AoC|4.5.5 HTTP Exploit ]]<br>+There are a nu