Unrated severityNVD Advisory· Published Sep 25, 2006· Updated Apr 16, 2026
CVE-2006-4977
CVE-2006-4977
Description
Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload, (b) ok_update, (c) image, and (d) path parameters, possibly requiring directory traversal sequences in the path parameter.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.morx.org/phpquiz.txtnvdExploit
- secunia.com/advisories/22015nvdVendor Advisory
- securityreason.com/securityalert/1627nvd
- www.securityfocus.com/archive/1/446315/100/0/threadednvd
- www.securityfocus.com/bid/20065nvd
- www.vupen.com/english/advisories/2006/3693nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28995nvd
- www.exploit-db.com/exploits/2376nvd
News mentions
0No linked articles in our index yet.