I have considered that too and although I must admit that you're most right about pointing it out, I decided to not care about security just yet simply because I was only trying to make some sort of proof-of-concept kind of thing. However, since I'm indeed planning of using a similar system into a real website I'm developing I will heed your warnings.
So thank you for bringing the security issue to my attention!
|