[eluser]jedd[/eluser]
[quote author="stuffradio" date="1259890669"]
Would it be insecure to store the value the user posted in a session of the MD5 password.
[/quote]
If not insecure per se, at least pointless or gratuitous.
Just store the user's login name - and if that's present, then you assume they've logged in.
The user can't insert this data into their session, so it's as safe as storing a hashed password and then doing whatever it is that you were thinking you could do with that hashed password to compare it (how?) to the database (on every page load?).
Unless there's some functionality that you're trying to achieve that I've missed.