Vulnerabilities > CVE-2007-0639 - Unspecified vulnerability in Guppy
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN guppy
exploit available
Summary
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | GuppY <= 4.5.16 Remote Commands Execution Exploit. CVE-2007-0639,CVE-2007-5845. Webapps exploit for php platform |
file | exploits/php/webapps/3221.php |
id | EDB-ID:3221 |
last seen | 2016-01-31 |
modified | 2007-01-29 |
platform | php |
port | |
published | 2007-01-29 |
reporter | rgod |
source | https://www.exploit-db.com/download/3221/ |
title | GuppY <= 4.5.16 - Remote Commands Execution Exploit |
type | webapps |
References
- http://osvdb.org/33016
- http://osvdb.org/33016
- http://retrogod.altervista.org/guppy_4516_cmd.html
- http://retrogod.altervista.org/guppy_4516_cmd.html
- http://secunia.com/advisories/23914
- http://secunia.com/advisories/23914
- http://securitytracker.com/id?1017569
- http://securitytracker.com/id?1017569
- http://www.vupen.com/english/advisories/2007/0421
- http://www.vupen.com/english/advisories/2007/0421
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31882
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31882
- https://www.exploit-db.com/exploits/3221
- https://www.exploit-db.com/exploits/3221