Back

CVE-2004-0030

CRITICAL

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

Published: Jan 20, 2004 Modified: Jun 16, 2026
CWE-829

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
phpgedview phpgedview 2.61

GitHub Security Advisory GHSA-xc2p-7wgh-ffh3

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and ...

References (12)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 7.35%

Top 6% most likely to be exploited

Threat Score 41.4 / 100

Data Sources

NVD EPSS GitHub