CAPEC-60: Reusing Session IDs (aka Session Replay)

This attack targets the reuse of valid session ID to spoof the target system in order to gain privileges. The attacker tries to reuse a stolen session ID used previously during a transaction to perform spoofing and session hijacking. Another name for this type of attack is Session Replay.

Severity
High
Likelihood
High
11
/ 100
low-risk
Active Threat 9/50 · Minimal
Exploit Availability 2/50 · Minimal