Vulnerabilities > Guppy > Guppy > 4.0

DATE CVE VULNERABILITY TITLE RISK
2014-02-06 CVE-2013-5983 Cross-Site Scripting vulnerability in Guppy
Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php.
network
guppy CWE-79
4.3
2007-03-14 CVE-2007-1451 Remote Security vulnerability in Guppy 4.0
GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting "Installation propre" (cleanup.php) and then "Suppression des fichiers d'installation" (delete.php).
network
low complexity
guppy
6.4