CVE Vulnerabilities

CVE-2005-1886

Published: Jun 09, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.

Affected Software

Name Vendor Start Version End Version
Yapig Yapig 0.92b (including) 0.92b (including)
Yapig Yapig 0.93u (including) 0.93u (including)
Yapig Yapig 0.94u (including) 0.94u (including)

References