Back
CVE-2005-4814
Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
Published: Dec 31, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| middlebury_college | segue_cms | * |
GitHub Security Advisory GHSA-p37h-9c34-5f75
Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server...
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.30%
Top 32% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub