TROYANOSYVIRUS
Volver a CVEs

CVE-2004-0595

N/A

Descripcion

The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado7/27/2004
Ultima modificacion4/16/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

avaya:converged_communications_serveravaya:integrated_managementavaya:s8300avaya:s8500avaya:s8700php:phpredhat:fedora_coretrustix:secure_linux

Referencias

http://marc.info/?l=bugtraq&m=108981780109154&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=108982983426031&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=109051444105182&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=109181600614477&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2004/dsa-531(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2005/dsa-669(af854a3a-2127-422b-91ae-364da2661108)
http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2004-392.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2004-395.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2004-405.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2005-816.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/10724(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.