Typical severity: High. An adversary utilizes a hash function extension/padding weakness, to modify the parameters passed to the web service requesting authentication by generating their own call in order to generate a legitimate signature hash (as described in the notes), without knowledge of the secret token sometimes provided by the web service.
Design: Use a secure message authentication code (MAC) function such as an HMAC-SHA1