Lucene search

K
cve[email protected]CVE-2005-4801
HistoryMay 15, 2006 - 4:00 p.m.

CVE-2005-4801

2006-05-1516:00:00
web.nvd.nist.gov
55
csrf
web security
yapig
php
image gallery
vulnerability
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.02 Low

EPSS

Percentile

89.0%

Multiple cross-site request forgery (CSRF) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to perform unauthorized actions as a logged-in user, as demonstrated by tricking the administrator to access a web page that performs a mod_info action in modify_gallery.php.

Affected configurations

NVD
Node
yapigyapigRange0.95b
OR
yapigyapigMatch0.92b
OR
yapigyapigMatch0.93u
OR
yapigyapigMatch0.94u
OR
yapigyapigMatch0.95

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.02 Low

EPSS

Percentile

89.0%

Related for CVE-2005-4801