Vulnerabilities > Phpx > Phpx > 3.2.3

DATE CVE VULNERABILITY TITLE RISK
2004-11-23 CVE-2004-0249 Multiple vulnerability in PHPx 3.2.3
PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.
network
low complexity
phpx
critical
10.0
2004-11-23 CVE-2004-0248 Multiple vulnerability in PHPx 3.2.3
Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.
network
phpx
6.8