7.5

CVE-2005-1881

Exploit
upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YapigYapig Version0.92b
YapigYapig Version0.93u
YapigYapig Version0.94u
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.43% 0.874
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

http://secunia.com/advisories/15600/
Vendor Advisory
Broken Link
http://securitytracker.com/id?1014103
Third Party Advisory
Vendor Advisory
Exploit
Broken Link
VDB Entry
http://secwatch.org/advisories/secwatch/20050530_yapig.txt
Vendor Advisory
Broken Link
http://www.osvdb.org/17115
Vendor Advisory
Broken Link