Session ID disclosure, crossite scripting.
vulners.com/securityvulns/securityvulns:doc:7373
vulners.com/securityvulns/securityvulns:doc:7374