PoC Index

CVE-2004-2364

MEDIUM 5.0EPSS 10.7%

Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
10.71% chance of exploitation in the next 30 days, 95th percentile
Published
2005-08-16
Updated
2024-08-08

ExploitDB entries (6)

References

Related