4 ms·
>Vendor stores database IDs in cookies which are easily spoofed (USERID_COOKIE), allowing all user information to be accessed. If this means what I think it me
by johnsoft 14y ago
>Vendor stores database IDs in cookies which are easily spoofed (USERID_COOKIE), allowing all user information to be accessed.
If this means what I think it means, why did it take until 2013 for this to be discovered?
- wuest 14y agoThis bug is not yet completely squashed in the wild: ' OR 1=1 --
- merlincorey 14y agoYou mean reported publicly.