AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2004-2363

MEDIUM · CVSS 4.3 EPSS 1.85%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-12-31 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2004-2363
Severity
MEDIUM
CVSS
4.3
EPSS
1.85%

Original Filing — NVD Description

Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) attacks via hex-encoded tags, which bypass the check for literal "<", ">", "(", and ")" characters, as demonstrated using the limit parameter to forums.php and a variety of other vectors.