MEDIUM · 6.8

CVE-2004-0595

The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be ...

Vulnerability Description

The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AvayaConverged Communications Server2.0
RedhatFedora Corecore_1.0
TrustixSecure Linux1.5
AvayaIntegrated ManagementAll versions
PhpPhp4.0
AvayaS8300r2.0.0
AvayaS8500r2.0.0
AvayaS8700r2.0.0

References

FAQ

What is CVE-2004-0595?

CVE-2004-0595 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be ...

How severe is CVE-2004-0595?

CVE-2004-0595 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0595?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Converged Communications Server, Redhat Fedora Core, Trustix Secure Linux, Avaya Integrated Management, Php Php.