CVE-2004-0066

phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgedview:phpgedview:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:47

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=107394912715478&w=2 - () http://marc.info/?l=bugtraq&m=107394912715478&w=2 -
References () http://www.osvdb.org/3464 - () http://www.osvdb.org/3464 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/14215 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/14215 -

Information

Published : 2004-02-17 05:00

Updated : 2024-11-20 23:47


NVD link : CVE-2004-0066

Mitre link : CVE-2004-0066

CVE.ORG link : CVE-2004-0066


JSON object : View

Products Affected

phpgedview

  • phpgedview