vendor:
TCExam
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: TCExam
Affected Version From: 11.2.2009
Affected Version To: 11.2.2011
Patch Exists: YES
Related CWE: N/A
CPE: a:tecnik:tcexam
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN), Apache 2.2.14 (Win32), PHP 5.3.1, MySQL 5.1.41
2011
TCExam <=11.2.011 Multiple SQL Injection Vulnerabilities
Input passed via multiple parameters to multiple scripts is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
Upgrade to version 11.2.012 or later