WebApp Sec mailing list archives

RE: Unable to impersonate another user although having its cookie


From: "Martin O'Neal" <martin.oneal () corsaire com>
Date: Wed, 1 Jul 2009 14:34:38 +0100


Is this possible? 

Ja; possible. May be tagging agent, or source address, or maybe using
multiple cookies, or maybe session ID in javascript variable...

Is it the normal operation 
in sessions in CakePHP?

No eye dear.

Martin...




Current thread: