CVE-2004-0595
Last modified
CVE-2004-0595 is a vulnerability of currently unknown severity. The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.. EPSS estimates a 45.16% chance of exploitation in the next 30 days.
Description
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Avaya | Converged Communications Server | 2.0 | — |
| Redhat | Fedora Core | core_1.0 | — |
| Redhat | Fedora Core | core_2.0 | — |
| Trustix | Secure Linux | 1.5 | — |
| Trustix | Secure Linux | 2.0 | — |
| Trustix | Secure Linux | 2.1 | — |
| Avaya | Integrated Management | All versions | — |
| Php | Php | 4.0 | — |
| Php | Php | 4.0.1 | — |
| Php | Php | 4.0.2 | — |
| Php | Php | 4.0.3 | — |
| Php | Php | 4.0.4 | — |
| Php | Php | 4.0.5 | — |
| Php | Php | 4.0.6 | — |
| Php | Php | 4.0.7 | — |
| Php | Php | 4.1.0 | — |
| Php | Php | 4.1.1 | — |
| Php | Php | 4.1.2 | — |
| Php | Php | 4.2.0 | — |
| Php | Php | 4.2.1 | — |
| Php | Php | 4.2.2 | — |
| Php | Php | 4.2.3 | — |
| Php | Php | 4.3.0 | — |
| Php | Php | 4.3.1 | — |
| Php | Php | 4.3.2 | — |
| Php | Php | 4.3.3 | — |
| Php | Php | 4.3.5 | — |
| Php | Php | 4.3.6 | — |
| Php | Php | 4.3.7 | — |
| Php | Php | 5.0 | Rc1 |
| Avaya | S8300 | r2.0.0 | — |
| Avaya | S8300 | r2.0.1 | — |
| Avaya | S8500 | r2.0.0 | — |
| Avaya | S8500 | r2.0.1 | — |
| Avaya | S8700 | r2.0.0 | — |
| Avaya | S8700 | r2.0.1 | — |
References
- http://www.debian.org/security/2004/dsa-531Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10724Exploit, Patch, Vendor Advisory
- http://www.debian.org/security/2004/dsa-531Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10724Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0595?
How severe is CVE-2004-0595?
How do I fix CVE-2004-0595?
Are you affected by CVE-2004-0595?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
