7.5
CVSSv2

CVE-2007-0639

Published: 31/01/2007 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and previous versions allow remote malicious users to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].

Vulnerable Product Search on Vulmon Subscribe to Product

guppy guppy

Exploits

<?php print_r(' --------------------------------------------------------------------------- Guppy <= 4516 remote commands execution exploit by rgod mail: retrog at alice dot it site: retrogodaltervistaorg dork: "Site powered by GuppY" | "Site créé avec GuppY" +inurl:lng= ----------------------------------------------------------- ...