LWN.net Logo

PHP: Cross site scripting vulnerability

Package(s):PHP CVE #(s):CAN-2003-0442
Created:July 2, 2003 Updated:August 13, 2003
Description: In PHP version 4.3.1 and earlier, when transparent session ID support is enabled using the "session.use_trans_sid" option, the session ID is not escaped before use. This allows a Cross Site Scripting attack.
Alerts:
Red Hat RHSA-2003:204-01 2003-07-02
OpenPKG OpenPKG-SA-2003.032 2003-07-07
Conectiva CLA-2003:691 2003-07-08
Debian DSA-351-1 2003-07-16
Yellow Dog YDU-20030710-2 2003-07-10
Mandrake MDKSA-2003:082 2003-08-04
Mandrake MDKSA-2003:082-1 2003-08-12

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.