{"api_version":"1","generated_at":"2026-07-23T11:10:11+00:00","cve":"CVE-2005-1881","urls":{"html":"https://cve.report/CVE-2005-1881","api":"https://cve.report/api/cve/CVE-2005-1881.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1881","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1881"},"summary":{"title":"CVE-2005-1881","description":"upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-06-06 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-434","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1014103","name":"http://securitytracker.com/id?1014103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"YaPiG Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Create/Delete Directories and Let Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15600/","name":"http://secunia.com/advisories/15600/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Secunia - Advisories - YaPiG Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/17115","name":"http://www.osvdb.org/17115","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt","name":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"SEC Watch – Keeping an Eye on Out","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1881","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1881","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1881","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yapig","cpe5":"yapig","cpe6":"0.92b","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1881","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yapig","cpe5":"yapig","cpe6":"0.93u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1881","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yapig","cpe5":"yapig","cpe6":"0.94u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.554Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15600","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15600/"},{"name":"17115","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/17115"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt"},{"name":"1014103","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014103"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-06-07T04:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15600","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15600/"},{"name":"17115","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/17115"},{"tags":["x_refsource_MISC"],"url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt"},{"name":"1014103","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014103"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1881","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15600","refsource":"SECUNIA","url":"http://secunia.com/advisories/15600/"},{"name":"17115","refsource":"OSVDB","url":"http://www.osvdb.org/17115"},{"name":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt","refsource":"MISC","url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt"},{"name":"1014103","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014103"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1881","datePublished":"2005-06-07T04:00:00.000Z","dateReserved":"2005-06-07T04:00:00.000Z","dateUpdated":"2024-09-16T23:40:55.265Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-06-06 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-434","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yapig:yapig:0.92b:*:*:*:*:*:*:*","matchCriteriaId":"1395410C-F729-4095-BC00-C15D61509A07"},{"vulnerable":true,"criteria":"cpe:2.3:a:yapig:yapig:0.93u:*:*:*:*:*:*:*","matchCriteriaId":"31FA4A81-65AD-4888-9F06-15C8E21D4907"},{"vulnerable":true,"criteria":"cpe:2.3:a:yapig:yapig:0.94u:*:*:*:*:*:*:*","matchCriteriaId":"2286772D-80C5-496F-8052-596AF41E7E98"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1881","Ordinal":"1","Title":"CVE-2005-1881","CVE":"CVE-2005-1881","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1881","Ordinal":"1","NoteData":"upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.","Type":"Description","Title":"CVE-2005-1881"},{"CveYear":"2005","CveId":"1881","Ordinal":"2","NoteData":"2005-06-07","Type":"Other","Title":"Published"}]}}}