CVE-2005-4468
PHPGedView <= 3.3.7 - Remote File Inclusion via PGV_BASE_DIRECTORY Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4468. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets PHPGedView <= 3.3.7, allowing remote command execution by injecting PHP code into log files and then executing it via a crafted request. The script provides a web interface for specifying the target host, path, command, and optional proxy settings.
Description
PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a URL in the PGV_BASE_DIRECTORY parameter.
Exploits (1)
This exploit targets PHPGedView <= 3.3.7, allowing remote command execution by injecting PHP code into log files and then executing it via a crafted request. The script provides a web interface for specifying the target host, path, command, and optional proxy settings.