CVE-2002-0121

PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.

Scoring

CVSS base score
0.01
EPSS probability
0.14%
Published
2002-06-25
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs