Unrated severityNVD Advisory· Published Jul 24, 2003· Updated Apr 16, 2026
CVE-2003-0442
CVE-2003-0442
Description
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- www.redhat.com/support/errata/RHSA-2003-204.htmlnvdPatchVendor Advisory
- shh.thathost.com/secadv/2003-05-11-php.txtnvdExploitPatchVendor Advisory
- distro.conectiva.com.br/atualizacoes/nvd
- marc.infonvd
- marc.infonvd
- www.ciac.org/ciac/bulletins/n-112.shtmlnvd
- www.debian.org/security/2003/dsa-351nvd
- www.mandriva.com/security/advisoriesnvd
- www.osvdb.org/4758nvd
- www.securityfocus.com/bid/7761nvd
- www.securitytracker.com/idnvd
- www.turbolinux.co.jp/security/2003/TLSA-2003-47j.txtnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/12259nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A485nvd
News mentions
0No linked articles in our index yet.