Description
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
Remediation
References
Related Vulnerabilities
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-0213)
WordPress Plugin SVG Support Cross-Site Scripting (2.4.2)
Joomla! Core 3.x.x Remote File Inclusion (3.0.0 - 3.2.5)
Oracle HTTP Server CVE-2013-1862 Vulnerability (CVE-2013-1862)
WordPress Plugin EWWW Image Optimizer Remote Code Execution (2.8.3)