peter bassill · operator
$ cve CVE-2003-0442 JSON

CVE-2003-0442 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 7% (pctl 94)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS6.98% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2003-07-24
Last modified2026-06-16

Affected (2)

VendorProduct
phpphp
redhatlinux

Public exploits

SourceTitleDate
exploit-dbPHP 4.x - Transparent Session ID Cross-Site Scripting2003-05-30

References

→ the Explorer  ·  watch your stack  ·  NVD