List: websecurity@lists.webappsec.org
From: Daniel "unicornFurnace" Crowley
[WEB SECURITY] SSO request hijack
Wed, Mar 14, 2012 6:12 PM
Second, placing data in the URL is considered unwise, as that data is
logged in various places like proxies, browser history and web logs.
Should an attacker gain access to any one of those items, they could
replay the session within the three minute validity period.