PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.
References
Link Resource
http://marc.info/?l=bugtraq&m=107340840209453&w=2 Mailing List Patch
http://secunia.com/advisories/10565 Broken Link Vendor Advisory
http://www.osvdb.org/3343 Broken Link
http://www.securityfocus.com/bid/9368 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1008632 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14159 Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2004-01-08T05:00:00

Updated: 2017-07-10T14:57:01

Reserved: 2004-01-06T00:00:00


Link: CVE-2004-0030

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2004-01-20T05:00:00.000

Modified: 2024-02-08T02:27:05.187


Link: CVE-2004-0030

JSON object: View

cve-icon Redhat Information

No data.

CWE