CVE-2008-2064
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems."
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.87%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- phpgedview/phpgedview
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29989Vendor Advisory
- http://secunia.com/advisories/30256Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=55456&release_id=595222Patch
- http://www.debian.org/security/2008/dsa-1580Patch
- http://www.phpgedview.net/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/28978
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42085
- http://secunia.com/advisories/29989Vendor Advisory
- http://secunia.com/advisories/30256Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=55456&release_id=595222Patch
- http://www.debian.org/security/2008/dsa-1580Patch
- http://www.phpgedview.net/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/28978
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42085
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.