Multiple vulnerabilities have been identified in GuppY, which could be exploited by attackers to execute arbitrary commands. These issues are due to input validation errors in the "error.php" script that does not validate the "REMOTE_ADDR" and "msg[][0]" variables, which could be exploited by remote attackers to inject abitrary commands and compromise a vulnerable web server.
Vulnerable Products
Vulnerable Software: GuppY version 4.5.16 and prior