CVE-2005-1881
Published Jun 6, 2005
Last updated 10 months ago
Overview
- Description
- upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-434
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:yapig:yapig:0.92b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1395410C-F729-4095-BC00-C15D61509A07" }, { "criteria": "cpe:2.3:a:yapig:yapig:0.93u:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31FA4A81-65AD-4888-9F06-15C8E21D4907" }, { "criteria": "cpe:2.3:a:yapig:yapig:0.94u:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2286772D-80C5-496F-8052-596AF41E7E98" } ], "operator": "OR" } ] } ]