CVE Vulnerabilities

CVE-2005-1886

Published: Jun 09, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.

Affected Software

NameVendorStart VersionEnd Version
YapigYapig0.92b (including)0.92b (including)
YapigYapig0.93u (including)0.93u (including)
YapigYapig0.94u (including)0.94u (including)

References