PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3873 | vdb entry |
http://www.iss.net/security_center/static/7908.php | vdb entry vendor advisory |
http://online.securityfocus.com/archive/1/250196 | mailing list patch |