Back

CVE-2005-4800

Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via the TestGallery parameter in a mod_info action to modify_gallery.php, which inserts the code into guid_info.php. NOTE: this issue is easier to exploit due to a separate CSRF vulnerability.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
yapig yapig *
yapig yapig 0.92b
yapig yapig 0.93u
yapig yapig 0.94u
yapig yapig 0.95

GitHub Security Advisory GHSA-gv3m-j4wj-2r64

Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and...

Risk Scores

CVSS Score 9.0 / 10
EPSS Score 2.17%

Top 19% most likely to be exploited

Threat Score 36.7 / 100

Data Sources

NVD EPSS GitHub