Race Condition
it all about make them go checking for thing and you will change that thing after they checking it and ofcourse before the job done
in php may be the back end server only handle one of the same cookie requests at time. so create another login session before exploit it.
more in my writeup "TCP OverClocking"