Reusing Session IDs (aka Session Replay)
CAPEC-60 · Detailed · Draft
This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The attacker tries to reuse a stolen session ID used previously during a transaction to perform spoofing and session hijacking. Another name for this type of attack is Session Replay.
likelihood: High
severity: High