Lucene search

K
nvd[email protected]NVD:CVE-2005-4800
HistoryDec 31, 2005 - 5:00 a.m.

CVE-2005-4800

2005-12-3105:00:00
web.nvd.nist.gov

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.3%

Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via the TestGallery parameter in a mod_info action to modify_gallery.php, which inserts the code into guid_info.php. NOTE: this issue is easier to exploit due to a separate CSRF vulnerability.

Affected configurations

NVD
Node
yapigyapigRange0.95b
OR
yapigyapigMatch0.92b
OR
yapigyapigMatch0.93u
OR
yapigyapigMatch0.94u
OR
yapigyapigMatch0.95

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.3%

Related for NVD:CVE-2005-4800