5
CVSSv2

CVE-2004-2364

Published: 31/12/2004 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 530
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 up to and including 3.2.6 allows remote malicious users to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpx phpx 3.2.4

phpx phpx 3.2.5

phpx phpx 3.1.0

phpx phpx 3.1.2

phpx phpx 3.0.4

phpx phpx 3.0.0

phpx phpx 3.1.4

phpx phpx 3.0.2

phpx phpx 3.0.1

phpx phpx 3.0.6

phpx phpx 3.2.0

phpx phpx 3.1.3

phpx phpx 3.2.2

phpx phpx 3.0.7

phpx phpx 3.1.1

phpx phpx 3.2.6

phpx phpx 3.2.3

phpx phpx 3.0.5

phpx phpx 3.2.1

phpx phpx 3.0.3

Exploits

source: wwwsecurityfocuscom/bid/10284/info It has been reported that PHPX is affected by multiple administrator command execution vulnerabilities These issues are due to a failure of the application to properly validate access to administrative commands This issue could permit a remote attacker to create a malicious URI link or emb ...
source: wwwsecurityfocuscom/bid/10284/info It has been reported that PHPX is affected by multiple administrator command execution vulnerabilities These issues are due to a failure of the application to properly validate access to administrative commands This issue could permit a remote attacker to create a malicious URI link or emb ...
source: wwwsecurityfocuscom/bid/10284/info It has been reported that PHPX is affected by multiple administrator command execution vulnerabilities These issues are due to a failure of the application to properly validate access to administrative commands This issue could permit a remote attacker to create a malicious URI link or emb ...
PHPX Multiple Vulnerabilities Vendor: PHPX Product: PHPX Version: <= 326 Website: wwwphpxorg BID: 10283 10284 CVE: CVE-2004-2364 OSVDB: 5903 5904 5905 5906 5907 5908 5909 5910 5911 SECUNIA: 11554 PACKETSTORM: 33251 Description: PHPX is a constantly evolving and changing Content Management System (CMS) PHPX is highly customizab ...
source: wwwsecurityfocuscom/bid/10284/info It has been reported that PHPX is affected by multiple administrator command execution vulnerabilities These issues are due to a failure of the application to properly validate access to administrative commands This issue could permit a remote attacker to create a malicious URI link or embed a ...
source: wwwsecurityfocuscom/bid/10284/info It has been reported that PHPX is affected by multiple administrator command execution vulnerabilities These issues are due to a failure of the application to properly validate access to administrative commands This issue could permit a remote attacker to create a malicious URI link or embed ...