Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-4865.
AI-analyzed exploit summary This Perl script exploits CVE-2006-4865 in PHPQuiz <= v1.2, demonstrating SQL injection to extract admin credentials and arbitrary file upload for remote code execution. It automates the attack by injecting SQL queries and uploading a PHP shell.
Description
Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors.
Exploits (1)
This Perl script exploits CVE-2006-4865 in PHPQuiz <= v1.2, demonstrating SQL injection to extract admin credentials and arbitrary file upload for remote code execution. It automates the attack by injecting SQL queries and uploading a PHP shell.