Vulnerability Description
Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_foot, and (3) template variables.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thomastsoi | Quirex | <= 2.0.2 |
Related Weaknesses (CWE)
References
- http://evuln.com/vulns/78/summary.htmlVendor Advisory
- http://secunia.com/advisories/18926Vendor Advisory
- http://www.securityfocus.com/archive/1/426188/100/0/threaded
- http://www.securityfocus.com/bid/16709
- http://www.vupen.com/english/advisories/2006/0641Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24672
- http://evuln.com/vulns/78/summary.htmlVendor Advisory
- http://secunia.com/advisories/18926Vendor Advisory
- http://www.securityfocus.com/archive/1/426188/100/0/threaded
- http://www.securityfocus.com/bid/16709
- http://www.vupen.com/english/advisories/2006/0641Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24672
FAQ
What is CVE-2006-0795?
CVE-2006-0795 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_f...
How severe is CVE-2006-0795?
CVE-2006-0795 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0795?
Check the references section above for vendor advisories and patch information. Affected products include: Thomastsoi Quirex.