Date:
18 October 2005
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Credential/Session Prediction
A bug in Gmail's authentication and session management allows direct login to anybodies account without requiring any involvement of the victim.
References: