Login security problem
If I logout of my administrator account, login as a less privileged user and then press the back button I can access all therestricted administrator pages I was looking at with the administrator account - if I close the browser and reopen, there's no problem. So I need to do something like delete cookies from the first login, or make the sessioin expire between logins or something...help please!
|