Vulnerability Details CVE-2004-0595
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.549
EPSS Ranking 97.9%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2004-0595
-
cpe:2.3:a:avaya:integrated_management:-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:h:avaya:converged_communications_server:2.0
-
cpe:2.3:h:avaya:s8300:r2.0.0
-
cpe:2.3:h:avaya:s8300:r2.0.1
-
cpe:2.3:h:avaya:s8500:r2.0.0
-
cpe:2.3:h:avaya:s8500:r2.0.1
-
cpe:2.3:h:avaya:s8700:r2.0.0
-
cpe:2.3:h:avaya:s8700:r2.0.1
-
cpe:2.3:o:redhat:fedora_core:core_1.0
-
cpe:2.3:o:redhat:fedora_core:core_2.0
-
cpe:2.3:o:trustix:secure_linux:1.5
-
cpe:2.3:o:trustix:secure_linux:2.0
-
cpe:2.3:o:trustix:secure_linux:2.1