Session Hijacking
CAPEC-593 · Standard · Stable
This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.
likelihood: High
severity: Very High