Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/11554 - | |
References | () http://securitytracker.com/id?1010061 - | |
References | () http://www.osvdb.org/5907 - | |
References | () http://www.osvdb.org/5908 - | |
References | () http://www.osvdb.org/5909 - | |
References | () http://www.osvdb.org/5910 - | |
References | () http://www.osvdb.org/5911 - | |
References | () http://www.phpx.org/project.php?action=view&project_id=1 - Patch, URL Repurposed | |
References | () http://www.securityfocus.com/archive/1/362230 - Exploit, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/10284 - Exploit, Patch |
14 Feb 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.phpx.org/project.php?action=view&project_id=1 - Patch, URL Repurposed |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:53
NVD link : CVE-2004-2364
Mitre link : CVE-2004-2364
CVE.ORG link : CVE-2004-2364
JSON object : View
Products Affected
phpx
- phpx
CWE