Vulnerability Name: | CVE-2002-0121 (CCN-7908) | ||||||||
Assigned: | 2002-01-13 | ||||||||
Published: | 2002-01-13 | ||||||||
Updated: | 2008-09-11 | ||||||||
Summary: | PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Jan 13 2002 - 11:56:27 CST PHP 4.x session spoofing Source: MITRE Type: CNA CVE-2002-0121 Source: BUGTRAQ Type: Patch 20020113 PHP 4.x session spoofing Source: XF Type: Vendor Advisory php-session-temp-disclosure(7908) Source: CCN Type: OSVDB ID: 2026 PHP4 Session Files Local Information Disclosure Source: BID Type: UNKNOWN 3873 Source: CCN Type: BID-3873 PHP4 Session Files Local Information Disclosure Vulnerability Source: XF Type: UNKNOWN php-session-temp-disclosure(7908) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |