Total vulnerabilities in the database
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
CVSS v2:
No CWE or OWASP classifications available.