Authenticating a user without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Phishing
Injection flaws
Session Fixation
Http Response splitting attack