VYPR
Unrated severityNVD Advisory· Published Jul 24, 2003· Updated Apr 16, 2026

CVE-2003-0442

CVE-2003-0442

Description

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

Affected products

3
  • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Range: <=4.3.1
  • Red Hat/Linux2 versions
    cpe:2.3:o:redhat:linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:linux:9.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

14

News mentions

0

No linked articles in our index yet.