CVE-2004-0030
CRITICALphpgedview 2.61 - Remote File Inclusion via PGV_BASE_DIRECTORY Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-0030. PoCs published by Windak.
AI-analyzed exploit summary The provided text describes a file inclusion vulnerability in PhpGedView, where remote attackers can manipulate the PGV_BASE_DIRECTORY parameter to include and execute malicious PHP scripts from external servers. The vulnerability affects multiple scripts in PhpGedView 2.61 and potentially other versions.
Description
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.
Exploits (1)
The provided text describes a file inclusion vulnerability in PhpGedView, where remote attackers can manipulate the PGV_BASE_DIRECTORY parameter to include and execute malicious PHP scripts from external servers. The vulnerability affects multiple scripts in PhpGedView 2.61 and potentially other versions.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H