CVE-2002-0121

PHP 4.0-4.1.1 - Session ID Exposure via Temporary File Storage

Title source: llm
STIX 2.1

Description

PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3873
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7908.php
Patch mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/250196

Scores

EPSS 0.0014
EPSS Percentile 33.9%

Details

Status published
Products (5)
php/php 4.0.4
php/php 4.0.5
php/php 4.0.6
php/php 4.1.0
php/php 4.1.2
Published Mar 25, 2002
Tracked Since Feb 18, 2026