Vulnerabilities > CVE-2008-2064 - Remote vulnerability in PhpGedView
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems."
Vulnerable Configurations
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1580.NASL |
description | It was discovered that phpGedView, an application to provide online access to genealogical data, allowed remote attackers to gain administrator privileges due to a programming error. Note: this problem was a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems. Resolving this problem was only possible by completely reworking the API, which is not considered appropriate for a security update. Since these are peripheral functions probably not used by the large majority of package users, it was decided to remove these interfaces. If you require that interface nonetheless, you are advised to use a version of phpGedView backported from Debian Lenny, which has a completely redesigned API. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 32402 |
published | 2008-05-22 |
reporter | This script is Copyright (C) 2008-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/32402 |
title | Debian DSA-1580-1 : phpgedview - programming error |
code |
|
References
- http://secunia.com/advisories/29989
- http://secunia.com/advisories/30256
- http://sourceforge.net/project/shownotes.php?group_id=55456&release_id=595222
- http://www.debian.org/security/2008/dsa-1580
- http://www.phpgedview.net/
- http://www.securityfocus.com/bid/28978
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42085