What is cookie poisoning?

In an InfoWorld article by Mandy Andress, she defines cookie poisoning as the modification of data stored in a cookie. Web sites often store on user systems cookies that include user IDs, passwords, account numbers, and so on. By changing these values, or "poisoning" the cookie, malicious users can gain access to accounts that are not their own.

Attackers can also steal a user's cookie and gain access to the user's account without having to enter an ID and password or other form of authentication.

