4.3
CVE-2005-2736
- EPSS 1.3%
- Veröffentlicht 30.08.2005 11:45:00
- Zuletzt bearbeitet 16.06.2026 22:15:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.3% | 0.666 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://marc.info/?l=bugtraq&m=112511025414488&w=2
https://exchange.xforce.ibmcloud.com/vulnerabilities/22020
http://cedri.cc/advisories/EXIF_XSS.txt
http://secunia.com/advisories/16596/
http://securitytracker.com/id?1014802
http://www.securityfocus.com/bid/14670