CVE-2006-1224
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.
Date published : 2006-03-14
http://www.securityfocus.com/bid/17068
http://www.securityfocus.com/archive/1/427329/100/0/threaded