Vulnerabilities > Guppy > Guppy > 4.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-02-06 | CVE-2013-5983 | Cross-Site Scripting vulnerability in Guppy Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php. | 4.3 |
2007-03-14 | CVE-2007-1451 | Remote Security vulnerability in Guppy 4.0 GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting "Installation propre" (cleanup.php) and then "Suppression des fichiers d'installation" (delete.php). | 6.4 |