Back
CVE-2004-2364
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (20)
| Vendor | Product | Version |
|---|---|---|
| phpx | phpx | 3.0.0 |
| phpx | phpx | 3.0.1 |
| phpx | phpx | 3.0.2 |
| phpx | phpx | 3.0.3 |
| phpx | phpx | 3.0.4 |
| phpx | phpx | 3.0.5 |
| phpx | phpx | 3.0.6 |
| phpx | phpx | 3.0.7 |
| phpx | phpx | 3.1.0 |
| phpx | phpx | 3.1.1 |
| phpx | phpx | 3.1.2 |
| phpx | phpx | 3.1.3 |
| phpx | phpx | 3.1.4 |
| phpx | phpx | 3.2.0 |
| phpx | phpx | 3.2.1 |
| phpx | phpx | 3.2.2 |
| phpx | phpx | 3.2.3 |
| phpx | phpx | 3.2.4 |
| phpx | phpx | 3.2.5 |
| phpx | phpx | 3.2.6 |
GitHub Security Advisory GHSA-4vc3-629x-6rhv
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers...
References (20)
- http://secunia.com/advisories/11554
- http://securitytracker.com/id?1010061
- http://www.osvdb.org/5907
- http://www.osvdb.org/5908
- http://www.osvdb.org/5909
- http://www.osvdb.org/5910
- http://www.osvdb.org/5911
- http://www.phpx.org/project.php?action=view&project_id=1 Patch, URL Repurposed
- http://www.securityfocus.com/archive/1/362230 Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/10284 Exploit, Patch
- http://secunia.com/advisories/11554
- http://securitytracker.com/id?1010061
- http://www.osvdb.org/5907
- http://www.osvdb.org/5908
- http://www.osvdb.org/5909
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
10.71%
Top 5% most likely to be exploited
Threat Score
23.2 / 100
Data Sources
NVD
EPSS
GitHub