Back

CVE-2004-2538

Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
nilesh_dosooye phpcodegenie *
nilesh_dosooye phpcodegenie 1.1
nilesh_dosooye phpcodegenie 1.4
nilesh_dosooye phpcodegenie 1.21
nilesh_dosooye phpcodegenie 3.0_alpha
nilesh_dosooye phpcodegenie 3.0_beta

GitHub Security Advisory GHSA-vf95-35wr-4pfv

Direct static code injection vulnerability in the PCG simple application generation in...

Risk Scores

CVSS Score 6.5 / 10
EPSS Score 2.29%

Top 18% most likely to be exploited

Threat Score 26.7 / 100

Data Sources

NVD EPSS GitHub