Vulnerabilities > Yappa NG

DATE CVE VULNERABILITY TITLE RISK
2007-11-15 CVE-2007-5994 Code Injection vulnerability in Yappa-Ng 2.3.2
PHP remote file inclusion vulnerability in check_noimage.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the config[path_src_include] parameter.
network
yappa-ng CWE-94
6.8
2005-05-02 CVE-2005-1311 Cross-Site Scripting vulnerability in Yappa-NG
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
yappa-ng
4.3
2005-04-24 CVE-2005-1312 Remote File Include vulnerability in Yappa-NG
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
network
low complexity
yappa-ng
7.5