Back

CVE-2005-3926

Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the _SERVER[REMOTE_ADDR] parameter, which is injected into a .inc script that is later included by the main script.

Published: Nov 30, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
guppy guppy 4.5
guppy guppy 4.5.3
guppy guppy 4.5.3a
guppy guppy 4.5.4
guppy guppy 4.5.9

GitHub Security Advisory GHSA-hw72-fhc8-8qf4

Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.12%

Top 13% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub