10753Third-party advisory
http://secunia.com/advisories/10753 CVE-2004-0128
PHPGedView 2.x - '[GED_File]_conf.php' Remote File Inclusion
Record summary
CVE-2004-0128 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHPGedView 2.x - '[GED_File]_conf.php' Remote File InclusionExploitDB exploitby Cedric CochinNot analyzed1 file
References
7sourceforge.netConfirmation
http://sourceforge.net/project/shownotes.php?release_id=141517 3769vdb entry
http://www.osvdb.org/3769 20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and priormailing list
http://www.securityfocus.com/archive/1/352355 9531vdb entry
http://www.securityfocus.com/bid/9531 phpgedview-gedfilconf-file-include(14987)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14987 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0128