vendor:
PhpGedView
by:
SecurityFocus
7.5
CVSS
HIGH
Multiple File Include Vulnerabilities
98
CWE
Product Name: PhpGedView
Affected Version From: 2.61
Affected Version To: 2.61
Patch Exists: Yes
Related CWE: N/A
CPE: a:phpgedview:phpgedview
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
PhpGedView Multiple File Include Vulnerabilities
PhpGedView is prone to multiple file include vulnerabilities. The source of the issue is that a number of scripts that ship with the software permit remote users to influence require() paths for various external files. This will permit remote attackers to cause malicious PHP scripts from attacker-controlled servers to be included and subsequently executed in the context of the web server hosting the vulnerable software.
Mitigation:
Upgrade to the latest version of PhpGedView