PHP Can a client ever set $_SESSION variables?

后端 未结 4 1056
谎友^
谎友^ 2020-12-30 00:48

Is there any scenario where a client/user/hacker can set $_SESSION variables themselves (excluding malicious software running on a server computer. I mostly mea

4条回答
  •  臣服心动
    2020-12-30 00:57

    Yes, it's possible. Read about Session poisoning and another quite common security issue Session fixation on Wikipedia or Google it - the web is full of articles about that.

提交回复
热议问题