AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-4426

MEDIUM · CVSS 4 EPSS 1.10%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-12-20 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.0. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2005-4426
Severity
MEDIUM
CVSS
4
EPSS
1.10%

Original NVD Description

Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in YaBB.