Required CVE Record Information
Description
Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the univers parameter in score.php and (2) the quiz_id parameter in home.php, accessed through the front/ URI.
References 8 Total
- exploit-db.com: 2376 exploit
- vupen.com: ADV-2006-3693 vdb-entry
- http://www.morx.org/phpquiz.txt
- securityreason.com: 1627 third-party-advisory
- secunia.com: 22015 third-party-advisory
- exchange.xforce.ibmcloud.com: phpquiz-score-sql-injection(28993) vdb-entry
- securityfocus.com: 20065 vdb-entry
- securityfocus.com: 20060916 PHPQuiz Multiple Remote Vulnerabilites mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- exploit-db.com: 2376 exploitx_transferred
- vupen.com: ADV-2006-3693 vdb-entryx_transferred
- http://www.morx.org/phpquiz.txt x_transferred
- securityreason.com: 1627 third-party-advisoryx_transferred
- secunia.com: 22015 third-party-advisoryx_transferred
- exchange.xforce.ibmcloud.com: phpquiz-score-sql-injection(28993) vdb-entryx_transferred
- securityfocus.com: 20065 vdb-entryx_transferred
- securityfocus.com: 20060916 PHPQuiz Multiple Remote Vulnerabilites mailing-listx_transferred