Vulnerabilities > Guppy > Guppy > 4.5.11
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-02-06 | CVE-2013-5983 | Cross-Site Scripting vulnerability in Guppy Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php. | 4.3 |
2006-03-14 | CVE-2006-1224 | Remote Directory Traversal vulnerability in GuppY Dwnld.PHP Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter. | 2.6 |