CVE-2004-2364
MEDIUM 5.0EPSS 10.7%
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 10.71% chance of exploitation in the next 30 days, 95th percentile
- Published
- 2005-08-16
- Updated
- 2024-08-08
ExploitDB entries (6)
- https://www.exploit-db.com/exploits/24092
- https://www.exploit-db.com/exploits/24091
- https://www.exploit-db.com/exploits/24090
- https://www.exploit-db.com/exploits/24089
- https://www.exploit-db.com/exploits/24088
- https://www.exploit-db.com/exploits/43812