Because UIDs are sequential (e.g., 1, 2, 3 …), an attacker can easily crawl through all profile pages by incrementing the uid parameter:

Thus, the same URL behaves differently depending on whether you are logged in as UID 898087 or as a different user—or not logged in at all.

Are you investigating a potential or unusual traffic log on your website?

But my finger slipped. I typed 7 instead of 6 at the end. I hit enter.