Description
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contest Gallery-Photo Contest for WordPress Security Bypass (13.1.0.6)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1963)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-0113)
Atlassian Jira Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6619)