Description
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2012-5083 Vulnerability (CVE-2012-5083)
WordPress Plugin Xorbin Analog Flash Clock Cross-Site Scripting (1.0)
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2009-2372)
WordPress Plugin Slider Hero with Animation, Video Background Cross-Site Scripting (8.4.3)