5
CVSSv2

CVE-2005-4467

Published: 22/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and previous versions allows remote malicious users to read and include arbitrary files via a .. (dot dot) in the PGV_BASE_DIRECTORY parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgedview phpgedview 2.61.1

phpgedview phpgedview 2.65

phpgedview phpgedview 2.65.1

phpgedview phpgedview 2.65.2

phpgedview phpgedview 2.60

phpgedview phpgedview 2.61

phpgedview phpgedview 2.52.3

phpgedview phpgedview 2.65_beta5

phpgedview phpgedview 3.3.7

Exploits

<?php # ---php_ged_view_337_xplphp 1631 20/12/2005 # # # # PHPGedView <= 337 remote commands execution # # coded by rgod # # ...