peter bassill · operator
$ cve CVE-2005-1881 JSON

CVE-2005-1881 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.4% (pctl 89)

Patch early

A public exploit exists.

Description

upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.43% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2005-06-06
Last modified2026-06-16

Affected (1)

VendorProduct
yapigyapig

Public exploits

SourceTitleDate
exploit-dbYaPiG 0.9x - Local/Remote File Inclusion2005-06-06

References

→ the Explorer  ·  watch your stack  ·  NVD