Back
CVE-2005-1884
Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.
Published: Jun 9, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| yapig | yapig | 0.92b |
| yapig | yapig | 0.93u |
| yapig | yapig | 0.94u |
GitHub Security Advisory GHSA-5f5c-9qpc-p4vg
Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0...
References (10)
- http://secunia.com/advisories/15600/
- http://securitytracker.com/id?1014103
- http://secwatch.org/advisories/secwatch/20050530_yapig.txt Exploit, Vendor Advisory
- http://www.osvdb.org/17120
- http://www.securityfocus.com/bid/13877 Exploit
- http://secunia.com/advisories/15600/
- http://securitytracker.com/id?1014103
- http://secwatch.org/advisories/secwatch/20050530_yapig.txt Exploit, Vendor Advisory
- http://www.osvdb.org/17120
- http://www.securityfocus.com/bid/13877 Exploit
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
2.57%
Top 16% most likely to be exploited
Threat Score
26.4 / 100
Data Sources
NVD
EPSS
GitHub