Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2)...
Vulnerability Description
Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload, (b) ok_update, (c) image, and (d) path parameters, possibly requiring directory traversal sequences in the path parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4977
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.exploit-db.com/exploits/2376
- http://www.vupen.com/english/advisories/2006/3693
- http://www.morx.org/phpquiz.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28995
- http://securityreason.com/securityalert/1627
- http://secunia.com/advisories/22015
- http://www.securityfocus.com/bid/20065
- http://www.securityfocus.com/archive/1/446315/100/0/threaded
Affected Vendor
walter beschmout
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.