A host or sysop has placed a hyperlink OUTSIDE of Web Crossing, leading to an item within Web Crossing, but failed to remove their user certificate from the URL (the user certificate is everything between the @ signs...the Web Crossing URL format is explained here in your documentation). A users certificate is valid for the amount of time specified in the General settings Control Panel "Minutes of inactivity until automatic logout". On an active site it is possible for other users to utilize the hyperlink before this period of time has elapsed, keeping the certificate valid. One way to help combat this is to turn on "A user certificate is only valid if it comes from the same IP address" in the Registered Users control panel or use the "HTTP Basic/Digest" login options available in 5.0+.
For example, a hyperlink URL shouldn't look like this: http://yoursite.com/webx?14@251.tcAEaP5aazO^2@.ee6d8c, but should be http://yoursite.com/webx?14@@.ee6d8c