PHP remote file inclusion vulnerability in (1) functions...
High severity
Unreviewed
Published
Apr 29, 2022
to the GitHub Advisory Database
•
Updated Feb 17, 2024
Description
Published by the National Vulnerability Database
Jan 20, 2004
Published to the GitHub Advisory Database
Apr 29, 2022
Last updated
Feb 17, 2024
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.
References