Welcome Guest, Not a member yet? Register   Sign In
Is it safe to use sessions for user validation?
#5

As others have pointed out, your handling of input data and using it in a query is not "robust". OK, since you don't show that code I'll give you the benefit of the doubt.

Session data does have some vulnerability through cookie hijacking. It is a complex subject. OWAP does a much better job of explaining the pit falls than I could - read this.
Reply


Messages In This Thread
RE: Is it safe to use sessions for user validation? - by dave friend - 06-17-2017, 06:35 PM



Theme © iAndrew 2016 - Forum software by © MyBB