MathiasDeWeerdt / webgoat

Automatically exported from code.google.com/p/webgoat
0 stars 0 forks source link

Session Fixation under Session Management Flaws, lowercase webgoat in the link, WebGoat required #54

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
What steps will reproduce the problem?
1. open the Session Fixation lesson
2. append &SID=whatever to the link in the message
3. in the next stage click the link, and you go noware

I should go to stage 3, but since the link in the message has webgoat instead 
of WebGoat at the link, it doesn't load the stage 3.

version 5.4 under WindowsXP SP3

Original issue reported on code.google.com by hen...@gmail.com on 26 Aug 2012 at 8:31

GoogleCodeExporter commented 9 years ago

Original comment by mayhe...@gmail.com on 17 Sep 2012 at 10:45

GoogleCodeExporter commented 9 years ago

Original comment by mayhe...@gmail.com on 17 Sep 2012 at 10:46