CVE-2004-2364
medium · 5Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.
5
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2004-12-31
Published
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| phpx | phpx | 3.0.0 |
| phpx | phpx | 3.0.1 |
| phpx | phpx | 3.0.2 |
| phpx | phpx | 3.0.3 |
| phpx | phpx | 3.0.4 |
| phpx | phpx | 3.0.5 |
| phpx | phpx | 3.0.6 |
| phpx | phpx | 3.0.7 |
| phpx | phpx | 3.1.0 |
| phpx | phpx | 3.1.1 |
| phpx | phpx | 3.1.2 |
| phpx | phpx | 3.1.3 |
| phpx | phpx | 3.1.4 |
| phpx | phpx | 3.2.0 |
| phpx | phpx | 3.2.1 |
| phpx | phpx | 3.2.2 |
| phpx | phpx | 3.2.3 |
| phpx | phpx | 3.2.4 |
| phpx | phpx | 3.2.5 |
| phpx | phpx | 3.2.6 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/11554
- http://securitytracker.com/id?1010061
- http://www.osvdb.org/5907
- http://www.osvdb.org/5908
- http://www.osvdb.org/5909
- http://www.osvdb.org/5910
- http://www.osvdb.org/5911
- http://www.phpx.org/project.php?action=view&project_id=1
- http://www.securityfocus.com/archive/1/362230
- http://www.securityfocus.com/bid/10284
- http://secunia.com/advisories/11554
- http://securitytracker.com/id?1010061
- http://www.osvdb.org/5907
- http://www.osvdb.org/5908
- http://www.osvdb.org/5909
- http://www.osvdb.org/5910
- http://www.osvdb.org/5911
- http://www.phpx.org/project.php?action=view&project_id=1
- http://www.securityfocus.com/archive/1/362230
- http://www.securityfocus.com/bid/10284
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-2364