CVE-2007-5845
GuppY <4.6.3, 4.5.16 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. NOTE: this can be leveraged to bypass authentication and upload arbitrary files by including admin/inc/upload.inc and specifying certain multipart/form-data input for admin/inc/upload.inc.
Exploits (2)
Scores
EPSS
0.0256
EPSS Percentile
85.6%
Details
CWE
CWE-94
Status
published
Products (2)
guppy/guppy
4.6.3
guppy/guppy
< 4.5.16
Published
Nov 06, 2007
Tracked Since
Feb 18, 2026