Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-0595


The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.


Published

2004-07-27T04:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware avaya converged_communications_server 2.0 Yes
Operating System redhat fedora_core core_1.0 Yes
Operating System redhat fedora_core core_2.0 Yes
Operating System trustix secure_linux 1.5 Yes
Operating System trustix secure_linux 2.0 Yes
Operating System trustix secure_linux 2.1 Yes
Application avaya integrated_management * Yes
Application php php 4.0 Yes
Application php php 4.0.1 Yes
Application php php 4.0.2 Yes
Application php php 4.0.3 Yes
Application php php 4.0.4 Yes
Application php php 4.0.5 Yes
Application php php 4.0.6 Yes
Application php php 4.0.7 Yes
Application php php 4.1.0 Yes
Application php php 4.1.1 Yes
Application php php 4.1.2 Yes
Application php php 4.2.0 Yes
Application php php 4.2.1 Yes
Application php php 4.2.2 Yes
Application php php 4.2.3 Yes
Application php php 4.3.0 Yes
Application php php 4.3.1 Yes
Application php php 4.3.2 Yes
Application php php 4.3.3 Yes
Application php php 4.3.5 Yes
Application php php 4.3.6 Yes
Application php php 4.3.7 Yes
Application php php 5.0 Yes
Application php php 5.0 Yes
Application php php 5.0 Yes
Hardware avaya s8300 r2.0.0 Yes
Hardware avaya s8300 r2.0.1 Yes
Hardware avaya s8500 r2.0.0 Yes
Hardware avaya s8500 r2.0.1 Yes
Hardware avaya s8700 r2.0.0 Yes
Hardware avaya s8700 r2.0.1 Yes

References