Among many other things, do you think your web server sees cookies? Yes, clearly, right? So do you think the server sees session IDs? Yes, clearly. So any session created in the last 2 years is presumed compromised. This is undergoing active exploitation at at least one Bitcoin exchange -- somebody came up with a list of session IDs and copy/pasta'd the cookies into their Firefox to check their balances. Checking balances: not nearly the most interesting thing you can accomplish after logging in as someone.
Not enough fun yet? Does your web server see page content? So any page content created in the last 2 years...