This whitepaper is called Local Session Poisoning in PHP Part 3: Bypassing Suhosin's Session Encryption.
b4c2757edc23926772d3931a43343d42a16d61a0d0eeaf402605d9c79122b967
This whitepaper is called Local Session Poisoning in PHP Part 2: Promiscuous Session Files.
a5b53f4b5bd46c66cfc9ad3a8d7d286455bc7a43f332c3b1e6ccb2290c69cb84
This whitepaper is called Local Session Poisoning in PHP Part 1: The Basics of Exploitation and How to Secure a Server.
c245f17fa9754ac7a72df98693b35929e796d3a655aeb50b5fa88d746027aa9e
Brief write up with a proof of concept explaining local session snooping in PHP.
a84ca642d685d472d8bdfa3fa84d30b724025d72ebec2bae38b90f52fc241d78
Brief write up with a proof of concept explaining local session hijacking in PHP.
c5099b1e7690d5d716238987cd3fe94c2ec425e441ee4155e5d47e1f6cad678e
phpMyAdmin versions below 3.3.10.3 and 3.4.3.2 suffer from a session manipulation vulnerability when the Swekey extension is activated.
4f0f8d6c23093df629d9ead3d0bece7eb8518e3b4ee9aeea91d3ae070f63ee29
phpMyAdmin Swekey remote code injection exploit that affects versions prior to 3.4.3.1 and versions prior to 3.3.10.2.
ad7c03013a93cbfc3a71ddcf1e0e7a96dc3afaf12cd89e7617e169215191b09f
phpMyAdmin version 3.x suffers from multiple remote code execution vulnerabilities.
2c8f67b34ff9e950a203c8d95cb5db1edaf669e76877d659e135f52bfce8de93