CVE
- Id
- 8555
- CVE No.
- CVE-2004-0127
- Status
- Candidate
- Description
- Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.
- Phase
- Modified (20071113)
- Votes
- ACCEPT(2) Baker, Green | NOOP(4) Armstrong, Cole, Cox, Wall
- Comments
- Green> Vendor ack"ed and provides an update; | http://prdownloads.sourceforge.net/phpgedview/phpGedView-2.65.2.zip?download