Vulnerabilities > CVE-2007-0639 - Remote Security vulnerability in GuppY

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
guppy
exploit available

Summary

Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].

Vulnerable Configurations

Part Description Count
Application
Guppy
1

Exploit-Db

descriptionGuppY <= 4.5.16 Remote Commands Execution Exploit. CVE-2007-0639,CVE-2007-5845. Webapps exploit for php platform
fileexploits/php/webapps/3221.php
idEDB-ID:3221
last seen2016-01-31
modified2007-01-29
platformphp
port
published2007-01-29
reporterrgod
sourcehttps://www.exploit-db.com/download/3221/
titleGuppY <= 4.5.16 - Remote Commands Execution Exploit
typewebapps