Dear All,
i have an e-commerce web application, i am applying payment with a third part, in order to do so the third parts gave me instructions, in order to do so. the instructions says that i have to create hidden field parameters and store amount and some valuable stuff.
the third parts also, requested that i create a hidden field with the session Id.
then when i click a button, the page is redirected to his website and then requested back.
well ....
my question is do the session id validation can prevent parameter manipulation.
Many Thanks
Mohamed ELMesseiry
Business System Analyst, Web Developer