vendor:
PhpGedView
by:
dun
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: PhpGedView
Affected Version From: 4.2.2003
Affected Version To: 4.2.2003
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
PhpGedView <= 4.2.3 Local File Inclusion Vulnerability
PhpGedView is a revolutionary genealogy program which allows users to view and edit their genealogy on their website. A vulnerability exists in PhpGedView versions 4.2.3 and earlier which allows an attacker to read arbitrary files on the server. This is done by exploiting the modules/ directory which is vulnerable to Local File Inclusion (LFI). By exploiting this vulnerability, an attacker can read the /etc/passwd file on the server.
Mitigation:
Upgrade to the latest version of PhpGedView, which is not vulnerable to this attack.