Vulnerability record · CVE-2004-0595 · published 27 July 2004
CVE-2004-0595: PHP strip_tags null-byte bypass enables XSS
Avaya · Converged Communications Server
PHP's strip_tags function in versions 4.x up to 4.3.7 and 5.x up to 5.0.0RC3 fails to strip null (\0) characters embedded in tag names when filtering input against an allowed-tag list. Browsers such as Internet Explorer and Safari ignore null characters, so tags that strip_tags should have removed are still parsed and executed. This undermines the common practice of using strip_tags as an XSS defense.
Description
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityA remotely reachable XSS filter bypass with public exploit references and very high EPSS, though it affects only legacy PHP versions and requires some user interaction.
What it is
PHP's strip_tags function in versions 4.x up to 4.3.7 and 5.x up to 5.0.0RC3 fails to strip null (\0) characters embedded in tag names when filtering input against an allowed-tag list. Browsers such as Internet Explorer and Safari ignore null characters, so tags that strip_tags should have removed are still parsed and executed. This undermines the common practice of using strip_tags as an XSS defense.
Impact
An attacker can inject script or other dangerous markup that survives strip_tags filtering and executes in a victim's browser, enabling cross-site scripting against users of the affected application.
Attack surface
Reached remotely over the network by submitting crafted input containing null bytes in tag names to any PHP application that relies on strip_tags for sanitization. No authentication is required per the CVSS vector (Au:N), though some user interaction is implied by the AC:M rating.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.45159, 98.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade PHP to a version after 4.3.7 or 5.0.0RC3, or apply the vendor patch referenced in the Debian, Red Hat, Gentoo, Mandrake and Novell advisories.
- Stop relying on strip_tags alone for XSS defense; apply context-aware output encoding (e.g. htmlspecialchars) before rendering user input.
- Strip or reject null bytes from user input at the application boundary before it reaches PHP string functions.
- Deploy a web application firewall or input validation layer that blocks null-byte sequences in request parameters.
- Audit existing code for strip_tags usage on user-controlled data and remediate those call sites.
Detection
- Search web and application logs for request parameters containing %00 or raw null bytes, especially inside HTML tag names.
- Grep application source for strip_tags calls handling user input and review whether output is additionally encoded.
- Monitor for reflected or stored script payloads in responses that bypass expected tag filtering.
- Use IDS/WAF signatures for null-byte injection patterns in HTTP requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0595 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0595), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.