Why is ASP.NET accepting externally created session identifiers?
I have an ASP.NET 3.5 Web Site using the standard SQL Membership Provider. The application has to pass the IBM Rational AppScan before we can push to production. I am getting the error: Severity: High Test Type: Application Vulnerable URL: http://mytestserver/myapp/login.aspx Remediation Tasks: Do not accept externally created session ...