Can any 1 explain me how jsessionid works with http request?
If some 1 gets to know my jsessionid ,is it possible for them to file a request with the same sessionid?