Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpgedview MEDIUM 5.0
CVE-2011-3778

PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

Mitigation only
Fix from $1,600 2011-09-24
Phpgedview MEDIUM 6.8
CVE-2011-0405EPSS 6%

Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote att…

Patch available
Fix from $1,600 2011-01-11
Phpgedview HIGH 10.0
CVE-2008-2064

Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the i…

Fix: after 4.1.4
Fix from $1,950 2008-05-02
Phpgedview HIGH 7.5
CVE-2005-4469

Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) th…

Fix: after 3.3.7
Fix from $1,950 2005-12-22
Phpgedview MEDIUM 5.0
CVE-2005-4467

Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files v…

Patch available
Fix from $1,600 2005-12-22
Phpgedview HIGH 7.5
CVE-2004-0127

Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execu…

Patch available
Fix from $1,950 2004-03-03
Phpgedview HIGH 7.5
CVE-2004-0128EPSS 8%

PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbit…

Patch available
Fix from $1,950 2004-03-03
Phpgedview MEDIUM 5.0
CVE-2004-0130

login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not conta…

Fix: after 2.65
Fix from $1,600 2004-03-03
Phpgedview HIGH 7.5
CVE-2004-0065

Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placeli…

Fix: after 2.65
Fix from $1,950 2004-02-17
Phpgedview MEDIUM 5.0
CVE-2004-0066

phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlis…

Fix: after 2.65
Fix from $1,600 2004-02-17
Phpgedview CRITICAL 9.8
CVE-2004-0030EPSS 7%

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remo…

Patch available
Fix from $2,300 2004-01-20
Phpgedview HIGH 7.5
CVE-2004-0031

PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.

Mitigation only
Fix from $1,950 2004-01-20
Phpgedview MEDIUM 6.8
CVE-2004-0032

Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the fir…

Mitigation only
Fix from $1,600 2004-01-20
Phpgedview MEDIUM 5.0
CVE-2004-0033

admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.

Mitigation only
Fix from $1,600 2004-01-20