CVE-2004-2364 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 10.7% (pctl 96)
Patch early
A public exploit exists.
Description
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 10.71% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| phpx | phpx |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHPX 3.x - '/page.php' Cross-Site Request Forgery / Arbitrary Command Execution | 2004-05-05 |
| exploit-db | PHPX 3.x - '/news.php' Cross-Site Request Forgery / Arbitrary Command Execution | 2004-05-05 |
| exploit-db | PHPX 3.x - '/user.php' Cross-Site Request Forgery / Arbitrary Command Execution | 2004-05-05 |
| exploit-db | PHPX 3.x - '/images.php' Cross-Site Request Forgery / Arbitrary Command Execution | 2004-05-05 |
| exploit-db | PHPX 3.x - '/forums.php' Cross-Site Request Forgery / Arbitrary Command Execution | 2004-05-05 |
| exploit-db | PHPX < 3.26 - Multiple Vulnerabilities | 2004-05-04 |
References
- http://secunia.com/advisories/11554
- http://securitytracker.com/id?1010061
- http://www.osvdb.org/5907
- http://www.osvdb.org/5908
- http://www.osvdb.org/5909
- http://www.osvdb.org/5910
- http://www.osvdb.org/5911
- http://www.phpx.org/project.php?action=view&project_id=1
- http://www.securityfocus.com/archive/1/362230
- http://www.securityfocus.com/bid/10284
- http://secunia.com/advisories/11554
- http://securitytracker.com/id?1010061
- http://www.osvdb.org/5907
- http://www.osvdb.org/5908
- http://www.osvdb.org/5909
- http://www.osvdb.org/5910
- http://www.osvdb.org/5911
- http://www.phpx.org/project.php?action=view&project_id=1
- http://www.securityfocus.com/archive/1/362230
- http://www.securityfocus.com/bid/10284
→ the Explorer · watch your stack · NVD