5

CVE-2005-2319

PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YawpYawp Version1.0.0
YawpYawp Version1.0.1
YawpYawp Version1.0.2
YawpYawp Version1.0.3
YawpYawp Version1.0.4
YawpYawp Version1.0.5
YawpYawp Version1.0.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://phpyawp.com/yawiki/index.php?page=ChangeLog
http://secunia.com/advisories/16049
http://www.hardened-php.net/advisory-102005.php
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/404948
Patch
Vendor Advisory
http://www.securityfocus.com/bid/14237
Patch