← Back

CVE-2005-1881

nvd nist
Published: Jun 6, 2005Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.

Affected (3)

Products: Yapig: Yapig
1 product
Yapig
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Yapig
Version 0.92b
Version 0.93u
Version 0.94u

References (8)

Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkExploitThird Party AdvisoryVDB EntryVendor Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitThird Party AdvisoryVDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory

Timeline

No history available yet.