Reported March 12, 2002, by Obscure.
Ipswitch IMail Server version 7.05 and earlier
When a user logs on to his or her account through the IMail Server Web interface, the application uses a unique URL to maintain the session authentication. By sending an HTML email message that references an image on another server, an attacker can easily obtain the unique URL via the referrer field in the HTTP header.
Discovered by Obscure.