Quote Originally Posted by Aardpsymon
That is rather scary....
Agreed - it's full control over the account.

Quote Originally Posted by nihil
Have cookies got anything to do with it?
Don't know but it works even on a logged-out account (i.e. any cookies presented would be expired so they shouldn't work).

Quote Originally Posted by nihil
just what is getting exploited or circumvented?
View of any existing mail message and the capability to send new mail on web mail accounts.

Quote Originally Posted by nihil
Does this only affect e-mail?
As far as I can tell.

Quote Originally Posted by nihil
Given the number of security "wannabes" out there I find it very strange that something so fundamental has gone unnoticed for so long
Agreed.