it is possible to test if the session token is exposed to this vulnerability and try to create a replay session attack. ???<br><br> ???[[ Session Riding AoC|4.5.4 Session Riding ]]<br> ???Session Riding descibes a way to force an unknowing user to execute unwanted actions on a web application in which he is currently authenticated. ???[[ HTTP Exploit AoC|4.5.5 HTTP Exploit ]]<br> ???Here is describ