Back
CVE-2005-4593
PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.
Published: Dec 31, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (6)
| Vendor | Product | Version |
|---|---|---|
| joshua_eichorn | phpdocumentor | 1.2 |
| joshua_eichorn | phpdocumentor | 1.2.1 |
| joshua_eichorn | phpdocumentor | 1.2.2 |
| joshua_eichorn | phpdocumentor | 1.2.3 |
| joshua_eichorn | phpdocumentor | 1.3_rc3 |
| joshua_eichorn | phpdocumentor | 1.3_rc4 |
GitHub Security Advisory GHSA-gwgp-42rc-9p7h
PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when...
References (18)
- http://rgod.altervista.org/phpdocumentor_130rc4_incl_expl.html Exploit
- http://secunia.com/advisories/18248
- http://securityreason.com/securityalert/303
- http://securitytracker.com/id?1015423
- http://www.osvdb.org/22114
- http://www.osvdb.org/22115
- http://www.securityfocus.com/archive/1/420441/100/0/threaded
- http://www.securityfocus.com/bid/16080 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23902
- http://rgod.altervista.org/phpdocumentor_130rc4_incl_expl.html Exploit
- http://secunia.com/advisories/18248
- http://securityreason.com/securityalert/303
- http://securitytracker.com/id?1015423
- http://www.osvdb.org/22114
- http://www.osvdb.org/22115
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
14.14%
Top 4% most likely to be exploited
Threat Score
34.2 / 100
Data Sources
NVD
EPSS
GitHub