CVE-2004-2363

PHPX 3.0-3.2.6 - Cross-Site Scripting via Hex-Encoded Tags

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2363. PoCs published by JeiAr.

AI-analyzed exploit summary The provided text describes multiple XSS vulnerabilities in PHPX due to improper sanitization of user-supplied URI input. It includes example URLs demonstrating how an attacker could inject malicious HTML or script code.

Description

Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) attacks via hex-encoded tags, which bypass the check for literal "<", ">", "(", and ")" characters, as demonstrated using the limit parameter to forums.php and a variety of other vectors.

Exploits (1)

exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24083

The provided text describes multiple XSS vulnerabilities in PHPX due to improper sanitization of user-supplied URI input. It includes example URLs demonstrating how an attacker could inject malicious HTML or script code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PHPX (version not specified)
No auth needed
Prerequisites: Victim must follow a malicious link
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Patch, URL Repurposed x_refsource_misc
http://www.phpx.org/project.php?action=view&project_id=1
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10283
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16065
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/362230

Scores

EPSS 0.0185
EPSS Percentile 76.3%

Details

Status published
Products (20)
phpx/phpx 3.0.0
phpx/phpx 3.0.1
phpx/phpx 3.0.2
phpx/phpx 3.0.3
phpx/phpx 3.0.4
phpx/phpx 3.0.5
phpx/phpx 3.0.6
phpx/phpx 3.0.7
phpx/phpx 3.1.0
phpx/phpx 3.1.1
... and 10 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026