Crossite scripting, session ID spoofing.
vulners.com/securityvulns/securityvulns:doc:2914
vulners.com/securityvulns/securityvulns:doc:2915