Hmmmm, so, someone is sniffing a browser session and picks up your sessionID? Seems like an outsider would need some clue as to the name of the individual vars. Of course, if he'd visited the site, and saw GET vars, for example, he'd have a clue.
Nothing is impenetrable, I suppose. However, since session vars are stored on the server, it'd be rather difficult, and above the level of your average script kiddie (#include disclaimer.h)
SSL would help in that sniffing the browser session and gaining the session ID would be nearly impossible....
KDK