CVE Vulnerabilities

CVE-2002-0121

Published: Mar 25, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp4.0.4 (including)4.0.4 (including)
PhpPhp4.0.5 (including)4.0.5 (including)
PhpPhp4.0.6 (including)4.0.6 (including)
PhpPhp4.1.0 (including)4.1.0 (including)
PhpPhp4.1.2 (including)4.1.2 (including)

References