Back

CVE-2005-2319

PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.

Published: Jul 19, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
yawp yawp 1.0.0
yawp yawp 1.0.1
yawp yawp 1.0.2
yawp yawp 1.0.3
yawp yawp 1.0.4
yawp yawp 1.0.5
yawp yawp 1.0.6

GitHub Security Advisory GHSA-pr8q-f7jx-h4v7

PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.35%

Top 31% most likely to be exploited

Threat Score 20.4 / 100

Data Sources

NVD EPSS GitHub