note 15310 added to function.session-start
| From: | php-general at lists dot php dot net | Date: | Wed, 05 Sep 2001 06:24:10 +0000 |
| Subject: | note 15310 added to function.session-start | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-17637@lists.php.net to get a copy of this message | ||
while reading alot about security here I'm noticed a couple of bugs on sites with getting into
the files without actually loging in at all. For example. I have read alot about never using the
variables instead use $HTTP_SESSION_VARS[example]. While doing this work with say this example.
www.test.com/search.php?num=1>-- the user is unable to log in to the site and is redirected. But
when trying it this way www.test.com/search?num=1 its then unlocked and lets me in and I'm free
to do as I please. Anybody have an explanation for that?
http://www.php.net/manual/en/function.session-start.php