20040316 PHPX 2.x - 3.2.4mailing list
http://archives.neohapsis.com/archives/bugtraq/2004-03/0154.html CVE-2004-0249
PHPX 3.2.3 - Multiple Vulnerabilities
Record summary
CVE-2004-0249 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHPX 3.2.3 - Multiple VulnerabilitiesExploitDB exploitby Manuel L?pezNot analyzed1 file
References
720040203 Multiple Vulnerabilities in PHPXmailing list
http://marc.info/?l=bugtraq&m=107586932324901&w=2 10797Third-party advisory
http://secunia.com/advisories/10797 9569vdb entry
http://www.securityfocus.com/bid/9569 phpx-cookie-account-hijacking(15052)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15052 phpx-session-hijack(15512)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15512 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0249