5
CVSSv2

CVE-2006-4977

Published: 25/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and previous versions allow remote malicious users to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload, (b) ok_update, (c) image, and (d) path parameters, possibly requiring directory traversal sequences in the path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

walter beschmout phpquiz

Exploits

###################################################### # # Title: PHPQuiz <= v12 Remote SQL injection/Code Execution Exploit # Vendor : PHPQuiz # webiste : wwwphpquizcom # Version : <= v12 # Severity: Critical # Author: Simo64 / simo64_at_morx_org # MorX Security Reseach Team # wwwmorxorg # wwwmorxorg/phpquiz ...