phpgedview records
17 published records for vendor phpgedview.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 11.8%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-0030Proof of concept | PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 alphpgedview · phpgedview · CWE-829 | Critical9.8 | — | 7.3% | Jan 20, 2004 |
41Plan | CVE-2008-2064No exploit | Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flawphpgedview · phpgedview | Critical10.0 | — | 1.9% | May 2, 2008 |
32Monitor | CVE-2004-0128Proof of concept | PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execphpgedview · phpgedview | High7.5 | — | 8.3% | Mar 3, 2004 |
32Monitor | CVE-2005-4468Proof of concept | PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary codphpgedview · phpgedview | High7.5 | — | 7.8% | Dec 21, 2005 |
31Monitor | CVE-2005-4469No exploit | Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code vphpgedview · phpgedview | High7.5 | — | 2.7% | Dec 21, 2005 |
31Monitor | CVE-2004-0127No exploit | Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary filesphpgedview · phpgedview | High7.5 | — | 2.2% | Mar 3, 2004 |
31Monitor | CVE-2004-0065No exploit | Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2phpgedview · phpgedview | High7.5 | — | 1.9% | Feb 17, 2004 |
30Monitor | CVE-2004-0031No exploit | PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconphpgedview · phpgedview | High7.5 | — | 1.5% | Jan 20, 2004 |
29Monitor | CVE-2011-0405Proof of concept | Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows rphpgedview · phpgedview · CWE-22 | Medium6.8 | — | 6.1% | Jan 10, 2011 |
28Monitor | CVE-2004-0032Proof of concept | Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script viphpgedview · phpgedview | Medium6.8 | — | 1.8% | Jan 20, 2004 |
21Monitor | CVE-2005-4467Proof of concept | Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrarphpgedview · phpgedview | Medium5.0 | — | 4.7% | Dec 21, 2005 |
21Monitor | CVE-2004-0033Proof of concept | admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.phpgedview · phpgedview | Medium5.0 | — | 2.8% | Jan 20, 2004 |
20Monitor | CVE-2004-0130No exploit | login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does phpgedview · phpgedview | Medium5.0 | — | 1.5% | Mar 3, 2004 |
20Monitor | CVE-2004-0066No exploit | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (phpgedview · phpgedview | Medium5.0 | — | 1.4% | Feb 17, 2004 |
20Monitor | CVE-2011-3778No exploit | PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installationphpgedview · phpgedview · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
18Monitor | CVE-2004-0067Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script phpgedview · phpgedview · CWE-79 | Medium4.3 | — | 3.1% | Feb 17, 2004 |
17Monitor | CVE-2007-5051No exploit | Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via thphpgedview · phpgedview · CWE-79 | Medium4.3 | — | 1.1% | Sep 23, 2007 |
- CVE-2004-003041Plan
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 al
CriticalCVSS 9.8Proof of conceptEPSS 7%phpgedview · phpgedviewJan 20, 2004
- CVE-2008-206441Plan
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw
CriticalCVSS 10.0No exploitEPSS 2%phpgedview · phpgedviewMay 2, 2008
- CVE-2004-012832Monitor
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to exec
HighCVSS 7.5Proof of conceptEPSS 8%phpgedview · phpgedviewMar 3, 2004
- CVE-2005-446832Monitor
PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary cod
HighCVSS 7.5Proof of conceptEPSS 8%phpgedview · phpgedviewDec 21, 2005
- CVE-2005-446931Monitor
Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code v
HighCVSS 7.5No exploitEPSS 3%phpgedview · phpgedviewDec 21, 2005
- CVE-2004-012731Monitor
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files
HighCVSS 7.5No exploitEPSS 2%phpgedview · phpgedviewMar 3, 2004
- CVE-2004-006531Monitor
Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2
HighCVSS 7.5No exploitEPSS 2%phpgedview · phpgedviewFeb 17, 2004
- CVE-2004-003130Monitor
PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editcon
HighCVSS 7.5No exploitEPSS 2%phpgedview · phpgedviewJan 20, 2004
- CVE-2011-040529Monitor
Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows r
MediumCVSS 6.8Proof of conceptEPSS 6%phpgedview · phpgedviewJan 10, 2011
- CVE-2004-003228Monitor
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script vi
MediumCVSS 6.8Proof of conceptEPSS 2%phpgedview · phpgedviewJan 20, 2004
- CVE-2005-446721Monitor
Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrar
MediumCVSS 5.0Proof of conceptEPSS 5%phpgedview · phpgedviewDec 21, 2005
- CVE-2004-003321Monitor
admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.
MediumCVSS 5.0Proof of conceptEPSS 3%phpgedview · phpgedviewJan 20, 2004
- CVE-2004-013020Monitor
login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does
MediumCVSS 5.0No exploitEPSS 2%phpgedview · phpgedviewMar 3, 2004
- CVE-2004-006620Monitor
phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (
MediumCVSS 5.0No exploitEPSS 1%phpgedview · phpgedviewFeb 17, 2004
- CVE-2011-377820Monitor
PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
MediumCVSS 5.0No exploitEPSS 1%phpgedview · phpgedviewSep 23, 2011
- CVE-2004-006718Monitor
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script
MediumCVSS 4.3Proof of conceptEPSS 3%phpgedview · phpgedviewFeb 17, 2004
- CVE-2007-505117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via th
MediumCVSS 4.3No exploitEPSS 1%phpgedview · phpgedviewSep 23, 2007