Vulnerabilities > CVE-2010-2153 - Unspecified vulnerability in Tecnick Tcexam 10.1.006/10.1.007
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in cache/. Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | TCExam 10.1.7 'admin/code/tce_functions_tcecode_editor.php' Arbitrary File Upload Vulnerability. CVE-2010-2153. Webapps exploit for php platform |
id | EDB-ID:34073 |
last seen | 2016-02-03 |
modified | 2010-06-02 |
published | 2010-06-02 |
reporter | John Leitch |
source | https://www.exploit-db.com/download/34073/ |
title | TCExam <= 10.1.7 - 'admin/code/tce_functions_tcecode_editor.php' Arbitrary File Upload Vulnerability |