Description
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in cache/.
Remediation
References
Related Vulnerabilities
Dotclear Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-7903)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-4893)
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-43824)
Moodle Improper Access Control Vulnerability (CVE-2015-2267)
Oracle Application Server Other Vulnerability (CVE-2005-1383)