CVE Vulnerabilities

CVE-2002-0121

Published: Mar 25, 2002 | Modified: Sep 11, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

Affected Software

Name Vendor Start Version End Version
Php Php 4.0.4 (including) 4.0.4 (including)
Php Php 4.0.5 (including) 4.0.5 (including)
Php Php 4.0.6 (including) 4.0.6 (including)
Php Php 4.1.0 (including) 4.1.0 (including)
Php Php 4.1.2 (including) 4.1.2 (including)

References