Lucene search

K
cve[email protected]CVE-2005-4800
HistoryMay 15, 2006 - 4:00 p.m.

CVE-2005-4800

2006-05-1516:00:00
web.nvd.nist.gov
19
cve-2005-4800
yapig
image gallery
php
code injection
vulnerability
csrf

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.3%

Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via the TestGallery parameter in a mod_info action to modify_gallery.php, which inserts the code into guid_info.php. NOTE: this issue is easier to exploit due to a separate CSRF vulnerability.

Affected configurations

NVD
Node
yapigyapigRange0.95b
OR
yapigyapigMatch0.92b
OR
yapigyapigMatch0.93u
OR
yapigyapigMatch0.94u
OR
yapigyapigMatch0.95

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.3%

Related for CVE-2005-4800