Can a user alter the value of $_SESSION in PHP?

后端 未结 4 1923
爱一瞬间的悲伤
爱一瞬间的悲伤 2020-12-01 07:31

this is crossing my mind and I\'m wondering if it is possible, how secure can it be to store info in the $_SESSION variable of PHP?

4条回答
  •  难免孤独
    2020-12-01 08:13

    Where as less secure $_COOKIES are on the client computer, the $_SESSION is stored on the server. It's location is determined by the session.save_path of php.ini. However there are still security issues such as session fixation

提交回复
热议问题