Back
CVE-2005-2319
PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.
Published: Jul 19, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (7)
| Vendor | Product | Version |
|---|---|---|
| yawp | yawp | 1.0.0 |
| yawp | yawp | 1.0.1 |
| yawp | yawp | 1.0.2 |
| yawp | yawp | 1.0.3 |
| yawp | yawp | 1.0.4 |
| yawp | yawp | 1.0.5 |
| yawp | yawp | 1.0.6 |
GitHub Security Advisory GHSA-pr8q-f7jx-h4v7
PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and...
References (10)
- http://phpyawp.com/yawiki/index.php?page=ChangeLog
- http://secunia.com/advisories/16049
- http://www.hardened-php.net/advisory-102005.php Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/404948 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/14237 Patch
- http://phpyawp.com/yawiki/index.php?page=ChangeLog
- http://secunia.com/advisories/16049
- http://www.hardened-php.net/advisory-102005.php Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/404948 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/14237 Patch
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
1.35%
Top 31% most likely to be exploited
Threat Score
20.4 / 100
Data Sources
NVD
EPSS
GitHub