<?xml version="1.0" encoding='utf-8'?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="card1" title="Session poisoning - Page 5 - Wikipedia">
<p>
<a accesskey="1" href="page.php?w=Session_poisoning&amp;p=4">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Session_poisoning&amp;p=6">3.Next</a>
</p>
<p>is subject to trivial attacks such as<pre>vulnerable.asp?login=YES&username=Mary</pre></p>

<p>This problem could exist in software where<br/>
*User submits username / password to <code>logon.asp</code><br/>
*If password for <code>Mary</code> checks out, <code>logon.asp</code> forwards to <code>vulnerable.asp?login=YES&username=Mary</code></p>

<p>The problem is that <code>vulnerable.asp</code> is designed on the assumption that the page is only accessed in a non-malicious way. Anyone who realizes how the script is designed, is able to craft</p><p>
<a accesskey="1" href="page.php?w=Session_poisoning&amp;p=4">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Session_poisoning&amp;p=6">3.Next</a>
</p>

<do type="prev" label="Search">
        <go href="search.wml"/>
</do>

</card>
</wml>
