[Phplib-users] php4 session saves whole obj properties, includeud db pass
Brought to you by:
nhruby,
richardarcher
From: Giancarlo <gia...@na...> - 2002-09-25 18:35:53
|
I am disappointed, again, in discovering that. every property of the class is saves, and in each /tmp/sess_ there's everything for the connection,included puser an pass in cleartext. phplib used to save only the persisten vars. ...my arms fall aside... Gian |