PT-2004-1248 · Phpgedview · Phpgedview

Published

2004-01-20

·

Updated

2017-10-10

·

CVE-2004-0033

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPGEDVIEW version 2.61
Description The issue allows remote attackers to obtain sensitive information. This is achieved by exploiting the action parameter in the "admin.php" endpoint with a phpinfo command.
Recommendations For PHPGEDVIEW version 2.61, consider restricting access to the "admin.php" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the action parameter with commands that can reveal sensitive information until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0033

Affected Products

Phpgedview