Back

CVE-2004-2364

Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (20)

Vendor Product Version
phpx phpx 3.0.0
phpx phpx 3.0.1
phpx phpx 3.0.2
phpx phpx 3.0.3
phpx phpx 3.0.4
phpx phpx 3.0.5
phpx phpx 3.0.6
phpx phpx 3.0.7
phpx phpx 3.1.0
phpx phpx 3.1.1
phpx phpx 3.1.2
phpx phpx 3.1.3
phpx phpx 3.1.4
phpx phpx 3.2.0
phpx phpx 3.2.1
phpx phpx 3.2.2
phpx phpx 3.2.3
phpx phpx 3.2.4
phpx phpx 3.2.5
phpx phpx 3.2.6

GitHub Security Advisory GHSA-4vc3-629x-6rhv

Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 10.71%

Top 5% most likely to be exploited

Threat Score 23.2 / 100

Data Sources

NVD EPSS GitHub