Vulnerabilities > CVE-2002-0121 - Local Information Disclosure vulnerability in PHP4 Session Files

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
php

Summary

PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

Vulnerable Configurations

Part Description Count
Application
Php
5