Back

CVE-2005-4593

PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
joshua_eichorn phpdocumentor 1.2
joshua_eichorn phpdocumentor 1.2.1
joshua_eichorn phpdocumentor 1.2.2
joshua_eichorn phpdocumentor 1.2.3
joshua_eichorn phpdocumentor 1.3_rc3
joshua_eichorn phpdocumentor 1.3_rc4

GitHub Security Advisory GHSA-gwgp-42rc-9p7h

PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 14.14%

Top 4% most likely to be exploited

Threat Score 34.2 / 100

Data Sources

NVD EPSS GitHub