First published: Mon Aug 29 2005(Updated: )
Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yapig | =0.95b | |
Yapig | =0.94u | |
Yapig | =0.93u | |
Yapig | =0.92b | |
Yapig | =0.95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2736 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2005-2736, upgrade YaPig to version 0.95c or later, where this vulnerability has been addressed.
CVE-2005-2736 affects YaPig versions 0.95 and earlier, including 0.94u, 0.93u, and 0.92b.
CVE-2005-2736 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
An attacker can exploit CVE-2005-2736 by injecting malicious scripts into EXIF data, such as the Camera Model Tag.