296,322
Total vulnerabilities in the database
Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the _SERVER[REMOTE_ADDR] parameter, which is injected into a .inc script that is later included by the main script.
Software | From | Fixed in |
---|---|---|
guppy / guppy | 4.5.4 | 4.5.4.x |
guppy / guppy | 4.5.3a | 4.5.3a.x |
guppy / guppy | 4.5.9 | 4.5.9.x |
guppy / guppy | 4.5 | 4.5.x |
guppy / guppy | 4.5.3 | 4.5.3.x |