Lots of people have 3rd party cookies turned off, so images/whatever from another server/domain won't have cookies attached.
If the sites are on the same server, you can use PHP's session hijacking, but the security issues around that are quite big, especially when search engines visit!