session security issue
| From: | Christian Dechery | Date: | Tue, 14 Aug 2001 11:42:22 +0000 |
| Subject: | session security issue | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-62614@lists.php.net to get a copy of this message | ||
I have pages that uses session for security that looks something like this:
<?php
session_start();
if( !isset($uid) )
{
include("include/auth.inc.php");
auth_user();
}
more code...
?>
so $uid tells me if the user is logged on or not...
but what if somebody calls the script directly from the address bar like this: http://server/script.php?uid=10
wouldn't this be a security problem?
____________________________
. Christian Dechery (lemming)
. http://www.tanamesa.com.br
. Gaita-L Owner / Web Developer