Question: An e-commerce website sets a cookie value to each user that arrives at its HTTP homepage. The cookie keeps track of the items the user
An e-commerce website sets a cookie value to each user that arrives at its HTTP homepage. The cookie keeps track of the items the user places in their cart. Upon checking out, the site authenticates the user over HTTPS, but keeps the same cookie value. This is an example of which vulnerability?
CHOOSE FROM THE OPTIONS BELOW: 1) Weak Session Management - Concurrent Sessions Allowed
2) Authorization Bypass - Application Flow
3) Weak Session Cookie - Predictable Session ID
4) Weak Session Managment - Session Fixation
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
