Back

CVE-2005-4814

Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
middlebury_college segue_cms *

GitHub Security Advisory GHSA-p37h-9c34-5f75

Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.30%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub