Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-06-09 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-1884
Mitre link : CVE-2005-1884
CVE.ORG link : CVE-2005-1884
JSON object : View
Products Affected
yapig
- yapig
CWE