CVE-2005-4469

N/A Unknown
Published: December 22, 2005 Modified: April 16, 2026
View on NVD

Description

Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, or the (2) user_language, (3) user_email, and (4) user_gedcomid parameters in login_register.php, which is directly inserted into authenticate.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/18177
Source: cve@mitre.org
Patch Vendor Advisory
http://www.osvdb.org/22010
Source: cve@mitre.org
http://www.securityfocus.com/bid/15983
Source: cve@mitre.org
Patch
http://rgod.altervista.org/phpgedview_337_xpl.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://secunia.com/advisories/18177
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://securitytracker.com/id?1015395
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/22010
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/419906/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/15983
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.vupen.com/english/advisories/2005/3033
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/23873
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.5%
85th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

phpgedview