note 39770 deleted from function.session-regenerate-id by nlopess

From: Date: Tue, 10 Feb 2004 18:31:19 +0000
Subject: note 39770 deleted from function.session-regenerate-id by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-64975@lists.php.net to get a copy of this message
Note Submitter: dizit@mail.ru ---- >>gmirchev at usa dot net For preventing session fixation attack you must unset possible variable not only in $_COOKIE. Session id may be passed including via GET, POST, requests. There is a need to unset session ID in $_COOKIE, $_GET, $_POST

« previous php.notes (#64975) next »