Session Variable Security

From: Date: Tue, 04 Jul 2000 05:09:20 +0000
Subject: Session Variable Security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-4683@lists.php.net to get a copy of this message
I read somewhere that you cannot directly change the value of a registered session variable using POST or GET- for *very important security reasons*. And that these must be explicitly reassigned values. Could anyone elaborate as to what these *very important security reasons* might be? -Morty

« previous php.general (#4683) next »