Vulnerabilities > CVE-2006-0628 - Remote Security vulnerability in Dale RAY Myquiz 1.01

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
dale-ray
exploit available

Summary

myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable.

Vulnerable Configurations

Part Description Count
Application
Dale_Ray
1

Exploit-Db

descriptionMyQuiz 1.01 (PATH_INFO) Arbitrary Command Execution Exploit. CVE-2006-0628. Webapps exploit for cgi platform
idEDB-ID:1471
last seen2016-01-31
modified2006-02-06
published2006-02-06
reporterHessam-x
sourcehttps://www.exploit-db.com/download/1471/
titleMyQuiz 1.01 PATH_INFO Arbitrary Command Execution Exploit