Vulnerabilities > Guppy > Guppy > 2.4.p1

DATE CVE VULNERABILITY TITLE RISK
2014-02-06 CVE-2013-5983 Cross-Site Scripting vulnerability in Guppy
Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php.
network
guppy CWE-79
4.3
2006-03-14 CVE-2006-1224 Remote Directory Traversal vulnerability in GuppY Dwnld.PHP
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.
network
high complexity
guppy
2.6