Lucene search

K
cveMitreCVE-2007-0639
HistoryJan 31, 2007 - 9:28 p.m.

CVE-2007-0639

2007-01-3121:28:00
mitre
web.nvd.nist.gov
25
cve-2007-0639
static code injection
guppy
remote attackers
php
.inc file
data directory
cookie
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.018

Percentile

88.2%

Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].

Affected configurations

Nvd
Node
guppyguppyRange4.5.16
VendorProductVersionCPE
guppyguppy*cpe:2.3:a:guppy:guppy:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.018

Percentile

88.2%