Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.
Conclusion & alert: CVE-2006-1224 is rated Exploit Available (59.2/100): CVSS Low severity, with high exploitation likelihood (EPSS 10.47%, 93th percentile). Core evidence: 5 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.27% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 1573 | exploit_db | edb | 2006-03-10 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-03 | 9.20% | 10.47% | +1.27% |
| 2 | 2025-07-25 | 9.49% | 9.20% | -0.30% |
| 3 | 2025-03-30 | — | 9.49% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.6 | 2.0 | LOW |
|
4.9 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| guppy | guppy | 2.4 | cpe:2.3:a:guppy:guppy:2.4:*:*:*:*:*:*:* |
| guppy | guppy | 2.4_p1 | cpe:2.3:a:guppy:guppy:2.4_p1:*:*:*:*:*:*:* |
| guppy | guppy | 2.4_p3 | cpe:2.3:a:guppy:guppy:2.4_p3:*:*:*:*:*:*:* |
| guppy | guppy | 2.4_p4 | cpe:2.3:a:guppy:guppy:2.4_p4:*:*:*:*:*:*:* |
| guppy | guppy | 4.5 | cpe:2.3:a:guppy:guppy:4.5:*:*:*:*:*:*:* |
| guppy | guppy | 4.5.3 | cpe:2.3:a:guppy:guppy:4.5.3:*:*:*:*:*:*:* |
| guppy | guppy | 4.5.3a | cpe:2.3:a:guppy:guppy:4.5.3a:*:*:*:*:*:*:* |
| guppy | guppy | 4.5.4 | cpe:2.3:a:guppy:guppy:4.5.4:*:*:*:*:*:*:* |
| guppy | guppy | 4.5.9 | cpe:2.3:a:guppy:guppy:4.5.9:*:*:*:*:*:*:* |
| guppy | guppy | 4.5.10 | cpe:2.3:a:guppy:guppy:4.5.10:*:*:*:*:*:*:* |
| guppy | guppy | 4.5.11 | cpe:2.3:a:guppy:guppy:4.5.11:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://secunia.com/advisories/19222 | Exploit Patch Vendor Advisory |
| http://securityreason.com/securityalert/569 | |
| http://securitytracker.com/id?1015753 | Exploit Patch Vendor Advisory |
| http://www.freeguppy.org/?lng=en | Patch |
| http://www.kapda.ir/advisory-291.html | Exploit Patch Vendor Advisory |
| http://www.osvdb.org/23846 | |
| http://www.osvdb.org/23993 | |
| http://www.securityfocus.com/archive/1/427329/100/0/threaded | |
| http://www.securityfocus.com/bid/17068 | Exploit Patch |
| http://www.vupen.com/english/advisories/2006/0936 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/25141 |