CVE-2004-0595

NameCVE-2004-0595
DescriptionThe strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-531, DSA-669-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php3sourcewoody3:3.0.18-23.1woody2DSA-669-1
php3source(unstable)3:3.0.18-27
php4sourcewoody4.1.2-7DSA-531
php4source(unstable)4:4.3.8-1

Search for package or bug name: Reporting problems