CVE-2005-4467
phpgedview 3.3.7 - Directory Traversal via PGV_BASE_DIRECTORY Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4467.
AI-analyzed exploit summary This PHP script exploits a remote command execution vulnerability in PHPGedView <= 3.3.7 by injecting PHP code into log files and executing arbitrary commands. It includes a web interface for inputting target details and supports proxy usage.
Description
Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the PGV_BASE_DIRECTORY parameter.
Exploits (1)
This PHP script exploits a remote command execution vulnerability in PHPGedView <= 3.3.7 by injecting PHP code into log files and executing arbitrary commands. It includes a web interface for inputting target details and supports proxy usage.