First published: Sat Dec 31 2005(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to perform unauthorized actions as a logged-in user, as demonstrated by tricking the administrator to access a web page that performs a mod_info action in modify_gallery.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yapig | =0.94u | |
Yapig | =0.93u | |
Yapig | =0.92b | |
Yapig | =0.95 | |
Yapig | <=0.95b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4801 is considered a moderate severity vulnerability due to its potential for unauthorized actions via CSRF.
To fix CVE-2005-4801, you should upgrade to a version of YaPIG that is later than 0.95b, which addresses the CSRF vulnerabilities.
CVE-2005-4801 affects YaPIG versions 0.95b and earlier, including versions 0.91 to 0.94u.
CVE-2005-4801 allows attackers to execute unauthorized actions as a logged-in user through cross-site request forgery (CSRF) techniques.
Users of YaPIG, particularly those with administrative access, are at risk from CVE-2005-4801 due to the CSRF vulnerabilities.