CVE-2004-2364

PHPX 3.0-3.2.6 - Cross-Site Request Forgery via Admin URL Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2004-2364. PoCs published by JeiAr, GulfTech Security.

AI-analyzed exploit summary The exploit describes a vulnerability in PHPX where an attacker can craft a malicious URI to execute administrative commands by tricking an administrator into activating it. This is due to improper access validation in the application.

Description

Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.

Exploits (6)

exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24090

The exploit describes a vulnerability in PHPX where an attacker can craft a malicious URI to execute administrative commands by tricking an administrator into activating it. This is due to improper access validation in the application.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: PHPX (version not specified)
No auth needed
Prerequisites: An administrator must be tricked into clicking a malicious link
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24088

The writeup describes a vulnerability in PHPX where an attacker can craft a malicious URI to execute administrative commands by tricking an administrator into activating it. The issue stems from improper access validation in the application.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: PHPX (version not specified)
No auth needed
Prerequisites: Administrator interaction required to activate the malicious URI
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24089

The exploit describes a vulnerability in PHPX where improper validation of administrative commands allows remote attackers to execute actions via malicious URIs. This could lead to privilege escalation if an administrator interacts with the crafted link.

Classification
Writeup 80%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: PHPX (version not specified)
No auth needed
Prerequisites: Administrator interaction with a malicious URI
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24091

The exploit describes a vulnerability in PHPX where an attacker can craft a malicious URI to execute administrative commands. The issue arises from improper access validation, allowing command execution in the context of an administrator.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: PHPX (version not specified)
No auth needed
Prerequisites: Access to craft a malicious URI · Administrator interaction required
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24092

The provided text describes multiple administrator command execution vulnerabilities in PHPX due to improper access validation. It outlines how an attacker could craft malicious URIs to execute administrative actions via XSS or direct URI manipulation.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: PHPX (version not specified)
No auth needed
Prerequisites: Victim must be an administrator · Victim must activate the malicious URI
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/43812

This is a detailed writeup describing multiple vulnerabilities in PHPX CMS, including XSS, path disclosure, and arbitrary command execution via unsafe GET requests. It provides examples of exploit vectors but does not include executable PoC code.

Classification
Writeup 100%
Attack Type
Xss | Info Leak | Other
Complexity
Trivial
Reliability
Reliable
Target: PHPX <= 3.26
No auth needed
Prerequisites: Access to vulnerable PHPX installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Patch, URL Repurposed x_refsource_misc
http://www.phpx.org/project.php?action=view&project_id=1
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5909
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1010061
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5908
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5911
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10284
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5910
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/362230
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11554
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5907

Scores

EPSS 0.1071
EPSS Percentile 95.2%

Details

Status published
Products (20)
phpx/phpx 3.0.0
phpx/phpx 3.0.1
phpx/phpx 3.0.2
phpx/phpx 3.0.3
phpx/phpx 3.0.4
phpx/phpx 3.0.5
phpx/phpx 3.0.6
phpx/phpx 3.0.7
phpx/phpx 3.1.0
phpx/phpx 3.1.1
... and 10 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026