uses the same folder to store all data from the session … Use cookies for session identifier, propagate, because if through a URL parameter, ….

PHP Session Security
Session Fixation
Session Hijacking
Session Sniffing
Session Prediction
Session Exposure
Session Poisoning
Session Injection
Insufficient Session Expiration
Best practices
Session lifetime control
Session identifier
Session cookie
Session data storage
Page and form tokens
