VYPR
Unrated severityNVD Advisory· Published Jul 24, 2003· Updated Jun 16, 2026

CVE-2003-0442

CVE-2003-0442

Description

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • PHP/PHP2 versions
    cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <=4.3.1
    • (no CPE)range: < 4.3.2
  • Red Hat/Linux2 versions
    cpe:2.3:o:redhat:linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:linux:9.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.