CVE-2005-4593

phpDocumentor <1.3.0 rc4 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1395

Scores

EPSS 0.2113
EPSS Percentile 95.7%

Details

Status published
Products (6)
joshua_eichorn/phpdocumentor 1.2
joshua_eichorn/phpdocumentor 1.2.1
joshua_eichorn/phpdocumentor 1.2.2
joshua_eichorn/phpdocumentor 1.2.3
joshua_eichorn/phpdocumentor 1.3_rc3
joshua_eichorn/phpdocumentor 1.3_rc4
Published Dec 31, 2005
Tracked Since Feb 18, 2026