{"api_version":"1","generated_at":"2026-07-23T09:29:56+00:00","cve":"CVE-2005-1886","urls":{"html":"https://cve.report/CVE-2005-1886","api":"https://cve.report/api/cve/CVE-2005-1886.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1886","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1886"},"summary":{"title":"CVE-2005-1886","description":"Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-06-09 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1014103","name":"http://securitytracker.com/id?1014103","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"YaPiG Bugs Let Remote Authenticated Users Execute Arbitrary Commands and Create/Delete Directories and Let Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15600/","name":"http://secunia.com/advisories/15600/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - YaPiG Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt","name":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"SEC Watch – Keeping an Eye on Out","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/17118","name":"http://www.osvdb.org/17118","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/13876","name":"http://www.securityfocus.com/bid/13876","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"YaPiG View.PHP Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/13875","name":"http://www.securityfocus.com/bid/13875","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"YaPiG View.PHP Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1886","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1886","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yapig","cpe5":"yapig","cpe6":"0.92b","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yapig","cpe5":"yapig","cpe6":"0.93u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1886","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yapig","cpe5":"yapig","cpe6":"0.94u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.239Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15600","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15600/"},{"name":"13876","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13876"},{"name":"13875","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13875"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt"},{"name":"1014103","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014103"},{"name":"17118","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/17118"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-06-07T04:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15600","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15600/"},{"name":"13876","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13876"},{"name":"13875","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13875"},{"tags":["x_refsource_MISC"],"url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt"},{"name":"1014103","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014103"},{"name":"17118","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/17118"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1886","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15600","refsource":"SECUNIA","url":"http://secunia.com/advisories/15600/"},{"name":"13876","refsource":"BID","url":"http://www.securityfocus.com/bid/13876"},{"name":"13875","refsource":"BID","url":"http://www.securityfocus.com/bid/13875"},{"name":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt","refsource":"MISC","url":"http://secwatch.org/advisories/secwatch/20050530_yapig.txt"},{"name":"1014103","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014103"},{"name":"17118","refsource":"OSVDB","url":"http://www.osvdb.org/17118"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1886","datePublished":"2005-06-07T04:00:00.000Z","dateReserved":"2005-06-07T04:00:00.000Z","dateUpdated":"2024-09-16T22:50:32.859Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-06-09 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yapig:yapig:0.92b:*:*:*:*:*:*:*","matchCriteriaId":"1395410C-F729-4095-BC00-C15D61509A07"},{"vulnerable":true,"criteria":"cpe:2.3:a:yapig:yapig:0.93u:*:*:*:*:*:*:*","matchCriteriaId":"31FA4A81-65AD-4888-9F06-15C8E21D4907"},{"vulnerable":true,"criteria":"cpe:2.3:a:yapig:yapig:0.94u:*:*:*:*:*:*:*","matchCriteriaId":"2286772D-80C5-496F-8052-596AF41E7E98"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1886","Ordinal":"1","Title":"CVE-2005-1886","CVE":"CVE-2005-1886","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1886","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.","Type":"Description","Title":"CVE-2005-1886"},{"CveYear":"2005","CveId":"1886","Ordinal":"2","NoteData":"2005-06-07","Type":"Other","Title":"Published"}]}}}