peter bassill · operator
$ cve CVE-2004-0249 JSON

CVE-2004-0249 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 4.9% (pctl 92)

Patch early

A public exploit exists.

Description

PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS4.93% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-23
Last modified2026-06-16

Affected (1)

VendorProduct
phpxphpx

Public exploits

SourceTitleDate
exploit-dbPHPX 3.2.3 - Multiple Vulnerabilities2004-02-03

References

→ the Explorer  ·  watch your stack  ·  NVD