← Vulnerability feed

Vulnerability record · CVE-2004-0595 · published 27 July 2004

CVE-2004-0595: PHP strip_tags null-byte bypass enables XSS

Avaya · Converged Communications Server

PHP's strip_tags function in versions 4.x up to 4.3.7 and 5.x up to 5.0.0RC3 fails to strip null (\0) characters embedded in tag names when filtering input against an allowed-tag list. Browsers such as Internet Explorer and Safari ignore null characters, so tags that strip_tags should have removed are still parsed and executed. This undermines the common practice of using strip_tags as an XSS defense.

6.8 CVSS 2.0 Medium EPSS 45% · top 1.3%
6.8CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityA remotely reachable XSS filter bypass with public exploit references and very high EPSS, though it affects only legacy PHP versions and requires some user interaction.

What it is

PHP's strip_tags function in versions 4.x up to 4.3.7 and 5.x up to 5.0.0RC3 fails to strip null (\0) characters embedded in tag names when filtering input against an allowed-tag list. Browsers such as Internet Explorer and Safari ignore null characters, so tags that strip_tags should have removed are still parsed and executed. This undermines the common practice of using strip_tags as an XSS defense.

Impact

An attacker can inject script or other dangerous markup that survives strip_tags filtering and executes in a victim's browser, enabling cross-site scripting against users of the affected application.

Attack surface

Reached remotely over the network by submitting crafted input containing null bytes in tag names to any PHP application that relies on strip_tags for sanitization. No authentication is required per the CVSS vector (Au:N), though some user interaction is implied by the AC:M rating.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.45159, 98.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade PHP to a version after 4.3.7 or 5.0.0RC3, or apply the vendor patch referenced in the Debian, Red Hat, Gentoo, Mandrake and Novell advisories.
  • Stop relying on strip_tags alone for XSS defense; apply context-aware output encoding (e.g. htmlspecialchars) before rendering user input.
  • Strip or reject null bytes from user input at the application boundary before it reaches PHP string functions.
  • Deploy a web application firewall or input validation layer that blocks null-byte sequences in request parameters.
  • Audit existing code for strip_tags usage on user-controlled data and remediate those call sites.

Detection

  • Search web and application logs for request parameters containing %00 or raw null bytes, especially inside HTML tag names.
  • Grep application source for strip_tags calls handling user input and review whether output is additionally encoded.
  • Monitor for reflected or stored script payloads in responses that bypass expected tag filtering.
  • Use IDS/WAF signatures for null-byte injection patterns in HTTP requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000847
http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023909.html
http://marc.info/?l=bugtraq&m=108981780109154&w=2
http://marc.info/?l=bugtraq&m=108982983426031&w=2
http://marc.info/?l=bugtraq&m=109051444105182&w=2
http://marc.info/?l=bugtraq&m=109181600614477&w=2
http://www.debian.org/security/2004/dsa-531 PatchVendor Advisory
http://www.debian.org/security/2005/dsa-669
http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:068
http://www.novell.com/linux/security/advisories/2004_21_php4.html
http://www.redhat.com/support/errata/RHSA-2004-392.html
http://www.redhat.com/support/errata/RHSA-2004-395.html
http://www.redhat.com/support/errata/RHSA-2004-405.html
http://www.redhat.com/support/errata/RHSA-2005-816.html
http://www.securityfocus.com/bid/10724 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/16692
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10619
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000847
http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023909.html
http://marc.info/?l=bugtraq&m=108981780109154&w=2
http://marc.info/?l=bugtraq&m=108982983426031&w=2
http://marc.info/?l=bugtraq&m=109051444105182&w=2
http://marc.info/?l=bugtraq&m=109181600614477&w=2
http://www.debian.org/security/2004/dsa-531 PatchVendor Advisory
http://www.debian.org/security/2005/dsa-669
http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:068
http://www.novell.com/linux/security/advisories/2004_21_php4.html
http://www.redhat.com/support/errata/RHSA-2004-392.html
http://www.redhat.com/support/errata/RHSA-2004-395.html
http://www.redhat.com/support/errata/RHSA-2004-405.html
http://www.redhat.com/support/errata/RHSA-2005-816.html
http://www.securityfocus.com/bid/10724 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/16692
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10619

Track CVE-2004-0595 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2004-1307Avaya call management system server vulnerabilityInteger overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …EPSS 6.3%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.2CVE-2011-1229Microsoft windows 2003 server null pointer dereference vulnerabilitywin32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Go…EPSS 1.5%7.2CVE-2004-0495Avaya converged communications server vulnerabilityMultiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse sou…EPSS 0.42%6.4CVE-2004-0493Apache httpd header parsing flaw causes memory exhaustion and possible heap overflowThe ap_get_mime_headers_core function in Apache httpd 2.0.49 mishandles long header lines containing many space or tab characters, causing memory exh…EPSS 85%analysed6.2CVE-2004-1235Avaya mn100 vulnerabilityRace condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10…EPSS 2.9%5.2CVE-2007-1491Avaya sip enablement services vulnerabilityApache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which expose…EPSS 0.37%5.1CVE-2004-0594PHP memory_limit abort race allows remote code executionPHP 4.x up to 4.3.7 and 5.x up to 5.0.0RC3 mishandle the memory_limit abort path, allowing a HashTable destructor pointer to be overwritten before ke…EPSS 55%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0595), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.