Quote:
Originally Posted by kh99
I haven't tried this and I'm not sure why sessionids are normally hidden, except that it makes the urls more readable, so maybe there's an issue with doing this that I don't understand.
|
Person A posts a link that includes his session ID
Person B follows that link while Person A's session is still active
Person B takes over Person A's session.
I used to work for an ecommerce company whose shopping cart/session ID was passed by a URL parameter. When a link went viral, it was not pretty.