VulnerabilityModified
CVE-2006-0795
Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_foot, and (3) template variables.
MEDIUM 5.0EPSS 2.96%
Does this matter?
Lower severity and a low EPSS score (2.96%). Track it; it rarely justifies an emergency change on its own.
Description
Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_foot, and (3) template variables.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.96% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- thomastsoi/quirex
- Source
- cve@mitre.org
References
- http://evuln.com/vulns/78/summary.htmlVendor Advisory
- http://secunia.com/advisories/18926Vendor Advisory
- http://www.securityfocus.com/archive/1/426188/100/0/threaded
- http://www.securityfocus.com/bid/16709
- http://www.vupen.com/english/advisories/2006/0641Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24672
- http://evuln.com/vulns/78/summary.htmlVendor Advisory
- http://secunia.com/advisories/18926Vendor Advisory
- http://www.securityfocus.com/archive/1/426188/100/0/threaded
- http://www.securityfocus.com/bid/16709
- http://www.vupen.com/english/advisories/2006/0641Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24672
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.