Typical severity: Very High. Likelihood of attack: Medium. Cross Site Tracing (XST) enables an adversary to steal the victim's session cookie and possibly other authentication credentials transmitted in the header of the HTTP request when the victim's browser communicates to a destination system's web server.
Administrators should disable support for HTTP TRACE at the destination's web server. Vendors should disable TRACE by default. | Patch web browser against known security origin policy bypass exploits.