shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tcexam | Tecnick.com | * | 4.0.011 (including) |