Tecnick.Com Tcexam vulnerabilities
4 known vulnerabilities affecting tecnick.com/tcexam.
Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2007-2430P3HIGHCVSS 7.8PoC≤ 4.0.0112007-05-02
CVE-2007-2430 [HIGH] CVE-2007-2430: shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PH
shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.
nvd
CVE-2007-2431P4MEDIUMCVSS 6.8PoC≤ 4.0.0112007-05-02
CVE-2007-2431 [MEDIUM] CVE-2007-2431: Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earl
Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web script via the _SERVER[SCRIPT_NAME] parameter.
nvd
CVE-2023-6554P3MEDIUMCVSS 6.5fixed in 15.1.02024-01-11
CVE-2023-6554 [MEDIUM] CWE-862 CVE-2023-6554: When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Ap
When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.
nvd
CVE-2007-6288P3HIGHCVSS 7.5≤ 5.1.0002007-12-10
CVE-2007-6288 [HIGH] CWE-89 CVE-2007-6288: Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute ar
Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd