Description
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
Avaya
Subscribe
Converged Communications Server
Subscribe
Integrated Management
Subscribe
S8300
Subscribe
S8500
Subscribe
S8700
Subscribe
Php
Subscribe
Php
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Fedora Core
Subscribe
Rhel Stronghold
Subscribe
Stronghold
Subscribe
Trustix
Subscribe
Secure Linux
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:24:26.176Z
Reserved: 2004-06-23T00:00:00.000Z
Link: CVE-2004-0595
No data.
Status : Modified
Published: 2004-07-27T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2004-0595
OpenCVE Enrichment
No data.
Weaknesses