Skip to content
Noroxi

phpgedview records

17 published records for vendor phpgedview.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
11.8%
Median publish → KEV
No record has entered KEV

All records

17 records
  • PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 al

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    phpgedview · phpgedviewJan 20, 2004

  • Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw

    CriticalCVSS 10.0No exploitEPSS 2%

    phpgedview · phpgedviewMay 2, 2008

  • CVE-2004-0128
    32Monitor

    PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to exec

    HighCVSS 7.5Proof of conceptEPSS 8%

    phpgedview · phpgedviewMar 3, 2004

  • CVE-2005-4468
    32Monitor

    PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary cod

    HighCVSS 7.5Proof of conceptEPSS 8%

    phpgedview · phpgedviewDec 21, 2005

  • CVE-2005-4469
    31Monitor

    Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code v

    HighCVSS 7.5No exploitEPSS 3%

    phpgedview · phpgedviewDec 21, 2005

  • CVE-2004-0127
    31Monitor

    Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files

    HighCVSS 7.5No exploitEPSS 2%

    phpgedview · phpgedviewMar 3, 2004

  • CVE-2004-0065
    31Monitor

    Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2

    HighCVSS 7.5No exploitEPSS 2%

    phpgedview · phpgedviewFeb 17, 2004

  • CVE-2004-0031
    30Monitor

    PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editcon

    HighCVSS 7.5No exploitEPSS 2%

    phpgedview · phpgedviewJan 20, 2004

  • CVE-2011-0405
    29Monitor

    Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows r

    MediumCVSS 6.8Proof of conceptEPSS 6%

    phpgedview · phpgedviewJan 10, 2011

  • CVE-2004-0032
    28Monitor

    Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script vi

    MediumCVSS 6.8Proof of conceptEPSS 2%

    phpgedview · phpgedviewJan 20, 2004

  • CVE-2005-4467
    21Monitor

    Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrar

    MediumCVSS 5.0Proof of conceptEPSS 5%

    phpgedview · phpgedviewDec 21, 2005

  • CVE-2004-0033
    21Monitor

    admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.

    MediumCVSS 5.0Proof of conceptEPSS 3%

    phpgedview · phpgedviewJan 20, 2004

  • CVE-2004-0130
    20Monitor

    login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does

    MediumCVSS 5.0No exploitEPSS 2%

    phpgedview · phpgedviewMar 3, 2004

  • CVE-2004-0066
    20Monitor

    phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (

    MediumCVSS 5.0No exploitEPSS 1%

    phpgedview · phpgedviewFeb 17, 2004

  • CVE-2011-3778
    20Monitor

    PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation

    MediumCVSS 5.0No exploitEPSS 1%

    phpgedview · phpgedviewSep 23, 2011

  • CVE-2004-0067
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script

    MediumCVSS 4.3Proof of conceptEPSS 3%

    phpgedview · phpgedviewFeb 17, 2004

  • CVE-2007-5051
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via th

    MediumCVSS 4.3No exploitEPSS 1%

    phpgedview · phpgedviewSep 23, 2007