PhpGedView Unspecified Remote Vulnerability
BID:28978
Info
PhpGedView Unspecified Remote Vulnerability
| Bugtraq ID: | 28978 |
| Class: | Unknown |
| CVE: |
CVE-2008-2064 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2008 12:00AM |
| Updated: | May 21 2008 01:44AM |
| Credit: | PhpGedView |
| Vulnerable: |
PhpGedView PhpGedView 4.1.4 PhpGedView PhpGedView 4.1.1 PhpGedView PhpGedView 4.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
PhpGedView PhpGedView 4.1.5 |
Discussion
PhpGedView Unspecified Remote Vulnerability
PhpGedView is prone to an unspecified vulnerability.
Successful exploits allow remote attackers to execute arbitrary script code with the privileges of the webserver user. This may facilitate the remote compromise of the underlying operating system.
Versions prior to PhpGedView 4.1.5 are vulnerable to this issue.
PhpGedView is prone to an unspecified vulnerability.
Successful exploits allow remote attackers to execute arbitrary script code with the privileges of the webserver user. This may facilitate the remote compromise of the underlying operating system.
Versions prior to PhpGedView 4.1.5 are vulnerable to this issue.
Exploit / POC
PhpGedView Unspecified Remote Vulnerability
Attackers can likely exploit this issue via a browser.
Attackers can likely exploit this issue via a browser.
Solution / Fix
PhpGedView Unspecified Remote Vulnerability
Solution:
Reportedly, the vendor has released updates, but Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has released updates, but Symantec has not confirmed this. Please contact the vendor for more information.