Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.
References
Link | Resource |
---|---|
http://www.kapda.ir/advisory-291.html | Exploit Patch Vendor Advisory |
http://www.freeguppy.org/?lng=en | Patch |
http://www.securityfocus.com/bid/17068 | Exploit Patch |
http://securitytracker.com/id?1015753 | Exploit Patch Vendor Advisory |
http://secunia.com/advisories/19222 | Exploit Patch Vendor Advisory |
http://www.osvdb.org/23846 | |
http://www.osvdb.org/23993 | |
http://securityreason.com/securityalert/569 | |
http://www.vupen.com/english/advisories/2006/0936 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25141 | |
http://www.securityfocus.com/archive/1/427329/100/0/threaded |
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-03-14 03:02
Updated : 2018-10-18 09:31
NVD link : CVE-2006-1224
Mitre link : CVE-2006-1224
JSON object : View
CWE
Products Affected
guppy
- guppy