PHPGEDVIEW 2.61 allows remote malicious users to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.
phpgedview phpgedview 2.61