Description
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.
References (5)
Core 5
Core References
Product x_refsource_confirm
http://tcexam.git.sourceforge.net/git/gitweb.cgi?p=tcexam/tcexam%3Ba=commit%3Bh=3e1ed3c02122eae182f076daabe903b0c8837971
Exploit x_refsource_misc
https://www.htbridge.com/advisory/HTB23111
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/50539
Patch x_refsource_confirm
http://sourceforge.net/projects/tcexam/files/CHANGELOG.TXT/view
Release Notes x_refsource_confirm
http://freecode.com/projects/tcexam/releases/347588
Scores
EPSS
0.0156
EPSS Percentile
72.6%
Details
CWE
CWE-89
Status
published
Products (50)
tecnick/tcexam
10.1.000
tecnick/tcexam
10.1.001
tecnick/tcexam
10.1.002
tecnick/tcexam
10.1.003
tecnick/tcexam
10.1.004
tecnick/tcexam
10.1.005
tecnick/tcexam
10.1.006
tecnick/tcexam
10.1.007
tecnick/tcexam
10.1.008
tecnick/tcexam
10.1.009
... and 40 more
Published
Nov 23, 2012
Tracked Since
Feb 18, 2026