Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.14269
Category:Web application abuses
Title:YaPiG Remote Server-Side Script Execution Vulnerability
Summary:The remote version of YaPiG may allow a remote attacker to execute; malicious scripts on a vulnerable system.
Description:Summary:
The remote version of YaPiG may allow a remote attacker to execute
malicious scripts on a vulnerable system.

Vulnerability Insight:
This issue exists due to a lack of sanitization of user-supplied data.
It is reported that an attacker may be able to upload content that will be saved on the server with a '.php'
extension. When this file is requested by the attacker, the contents of the file will be parsed and executed by the
PHP engine, rather than being sent.

Vulnerability Impact:
Successful exploitation of this issue may allow an attacker to execute malicious
script code on a vulnerable server.

Solution:
Upgrade to YaPiG 0.92.2 or later.

CVSS Score:
5.8

CVSS Vector:
AV:A/AC:L/Au:N/C:P/I:P/A:P

CopyrightCopyright (C) 2004 David Maciejak

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.