CVE Vulnerabilities

CVE-2010-2153

Published: Jun 03, 2010 | Modified: Jun 04, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in cache/.

Affected Software

Name Vendor Start Version End Version
Tcexam Tecnick 10.1.006 (including) 10.1.006 (including)
Tcexam Tecnick 10.1.007 (including) 10.1.007 (including)

References