Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a %2E. (mixed encoding) in the pg parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Guppy | Guppy | 2.4 (including) | 2.4 (including) |
| Guppy | Guppy | 2.4_p1 (including) | 2.4_p1 (including) |
| Guppy | Guppy | 2.4_p3 (including) | 2.4_p3 (including) |
| Guppy | Guppy | 2.4_p4 (including) | 2.4_p4 (including) |
| Guppy | Guppy | 4.5 (including) | 4.5 (including) |
| Guppy | Guppy | 4.5.3 (including) | 4.5.3 (including) |
| Guppy | Guppy | 4.5.3a (including) | 4.5.3a (including) |
| Guppy | Guppy | 4.5.4 (including) | 4.5.4 (including) |
| Guppy | Guppy | 4.5.9 (including) | 4.5.9 (including) |
| Guppy | Guppy | 4.5.10 (including) | 4.5.10 (including) |
| Guppy | Guppy | 4.5.11 (including) | 4.5.11 (including) |