Code: Select all
<?
session_start();
$_SESSION['x']="x";
session_register("register");
$register="y";
?>
<iframe src=x.php></iframe>
<? X.PHP
session_start();
$id=session_id();
print<<<end
$register $_SESSION['x'] $id
end;
?>y cb05f6258e0fcdcbdde750ab3af85845
so the registred variable $y and the session_id appears in iframe but not the variable $_SESSION['x']...
???
ps. aha in php.ini i got
session.use_trans_sid = 1
url_rewriter.tags=
"a=href,area=href,frame=src,input=src,form=fakeentry,iframe=src"
and register_globals = on
(if it may help...)