CVE-2007-0639
GuppY <4.5.16 - Code Injection
Title source: llmDescription
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].
Exploits (1)
References (7)
Scores
EPSS
0.1068
EPSS Percentile
93.3%
Details
Status
published
Products (1)
guppy/guppy
< 4.5.16
Published
Jan 31, 2007
Tracked Since
Feb 18, 2026