9.8
CVSSv3

CVE-2004-0030

Published: 20/01/2004 Updated: 08/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote malicious users to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgedview phpgedview 2.61

Exploits

source: wwwsecurityfocuscom/bid/9368/info PhpGedView is prone to multiple file include vulnerabilities The source of the issue is that a number of scripts that ship with the software permit remote users to influence require() paths for various external files This will permit remote attackers to cause malicious PHP scripts from attacker- ...