6.8
CVE-2004-0595
- EPSS 54.88%
- Published 27.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
Data is provided by the National Vulnerability Database (NVD)
Avaya ≫ Converged Communications Server Version2.0
Redhat ≫ Fedora Core Versioncore_1.0
Redhat ≫ Fedora Core Versioncore_2.0
Trustix ≫ Secure Linux Version1.5
Trustix ≫ Secure Linux Version2.0
Trustix ≫ Secure Linux Version2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 54.88% | 0.98 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|