CVE

CVE-2005-4801

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2005
Last modified:
20/07/2017

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to perform unauthorized actions as a logged-in user, as demonstrated by tricking the administrator to access a web page that performs a mod_info action in modify_gallery.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yapig:yapig:*:*:*:*:*:*:*:* 0.95b (including)
cpe:2.3:a:yapig:yapig:0.92b:*:*:*:*:*:*:*
cpe:2.3:a:yapig:yapig:0.93u:*:*:*:*:*:*:*
cpe:2.3:a:yapig:yapig:0.94u:*:*:*:*:*:*:*
cpe:2.3:a:yapig:yapig:0.95:*:*:*:*:*:*:*