|
Posted by The Natural Philosopher on 09/28/17 12:02
flowover wrote:
> On Jan 28, 12:04 pm, The Natural Philosopher <a...@b.c> wrote:
>> Greg N. wrote:
>>> Is there a way to pass (POST) data from one page (script) to another
>>> other than using a FORM? I don't want to use GET either.
>> Well not really, but its perfectly possible to have a form with no
>> submit button and no user accessible variables.
>>
>> So whose to know if its a form or not?
>
> Never assume the end user does not have 'access' to values that you
> echo as hidden fields. Security disaster waiting to happen.
Oh, sure. You can source dump and read em.
I thought it was an appearance issue, not a security one.
Navigation:
[Reply to this message]
|