LWN.net Logo

PHP: Cross site scripting vulnerability

Package(s):PHP CVE #(s):CAN-2003-0442
Created:July 2, 2003 Updated:August 13, 2003
Description: In PHP version 4.3.1 and earlier, when transparent session ID support is enabled using the "session.use_trans_sid" option, the session ID is not escaped before use. This allows a Cross Site Scripting attack.
Alerts:
Mandrake MDKSA-2003:082-1 2003-08-12
Mandrake MDKSA-2003:082 2003-08-04
Yellow Dog YDU-20030710-2 2003-07-10
Debian DSA-351-1 2003-07-16
Conectiva CLA-2003:691 2003-07-08
OpenPKG OpenPKG-SA-2003.032 2003-07-07
Red Hat RHSA-2003:204-01 2003-07-02

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds