Yes, the article does mention session secrets. However, this exploit does not require session secrets. The person who wrote the blog post wrote about essentially two vulnerabilities: session forging and SQL injection.
EDIT Well... he might, but I've never seen him do it. He's a security professional, after all.
(I wouldn't have said it was possible unless I had a curl line that did it, for what it's worth.)