WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.
Publication date: Mon, 31 Dec 2001 11:00:00 +0000