View Single Post
Old 12-06-2007, 02:58 AM   #3 (permalink)
trmbne2000
The Wanderer
 
Join Date: Nov 2007
Posts: 13
Thanks: 0
trmbne2000 is on a distinguished road
Default

I have permissions in my actual script already. Say that I am User #27, someone could send a post to the ajax page using userID of 27. Say User #27 has permission to do the requested action, the forged post could perform the action even though user #27 isn't actually logged in.
trmbne2000 is offline  
Reply With Quote