VYPR
Unrated severityNVD Advisory· Published May 2, 2007· Updated Apr 23, 2026

CVE-2007-2430

CVE-2007-2430

Description

shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.

Affected products

1
  • cpe:2.3:a:tecnick.com:tcexam:*:*:*:*:*:*:*:*
    Range: <=4.0.011

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.