CVE Vulnerabilities

CVE-2005-4799

Published: Dec 31, 2005 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Homepage field (aka the Website field) in an image-related comment and (2) the img_size field in view.php. NOTE: due to lack of details from the researcher, it is not clear whether the comment vector overlaps CVE-2005-1886.

Affected Software

Name Vendor Start Version End Version
Yapig Yapig * 0.95b (including)
Yapig Yapig 0.92b (including) 0.92b (including)
Yapig Yapig 0.93u (including) 0.93u (including)
Yapig Yapig 0.94u (including) 0.94u (including)
Yapig Yapig 0.95 (including) 0.95 (including)

References