7.5
CVSSv2

CVE-2004-0128

Published: 03/03/2004 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and previous versions allows remote malicious users to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgedview phpgedview 2.65.1

phpgedview phpgedview 2.61.1

phpgedview phpgedview 2.65

phpgedview phpgedview 2.60

phpgedview phpgedview 2.61

phpgedview phpgedview 2.52.3

Exploits

source: wwwsecurityfocuscom/bid/9531/info It has been reported that PhpGedView may be prone to a remote file include vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system The problem reportedly exists because remote users may influence the 'PGV_BASE_DIRECTORY' ...