Session poisoning

from Wikipedia, the free encyclopedia

Session poisoning , also known as session data pollution or session modification , describes the exploitation of a security gap in server programs in which the input data is insufficiently checked. This enables an attacker to modify the session data, i.e. to poison it metaphorically.