Vulnerabilities > CVE-2004-2363 - Unspecified vulnerability in PHPx

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
phpx
exploit available

Summary

Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) attacks via hex-encoded tags, which bypass the check for literal "<", ">", "(", and ")" characters, as demonstrated using the limit parameter to forums.php and a variety of other vectors.

Exploit-Db

descriptionPHPX 3.x Multiple Cross-Site Scripting Vulnerabilities. CVE-2004-2363. Webapps exploit for php platform
idEDB-ID:24083
last seen2016-02-02
modified2004-05-05
published2004-05-05
reporterJeiAr
sourcehttps://www.exploit-db.com/download/24083/
titlePHPX 3.x - Multiple Cross-Site Scripting Vulnerabilities