000webhost Vulnerable to session hijack attack

Step1:  Download the Wireshark tool used to sniff the traffic.

Step2: Start the capture mode and sniff the traffic using wireshark tool.

Step3: Log in to 000webhost account.

Step4: Now,go to wireshark and stop the capture mode and find the link as given below:

  http://members.000webhost.com/index.php?login_hash=TNieMODE1MgAf6ko

Step5: Copy the above link and paste on your browser and log in to 000webhost account without  credential