State Variable Manipulation
-  The HTTP protocol is stateless 
 
-  A number of different mechanisms are used to store state:
-  Cookies 
 
-  Hidden fields
 
-  Parameters
 
 
-  These entities are typically not protected 
 
-  Attackers can manipulate these entities to alter their identity or authorization