VYPR
Unrated severityNVD Advisory· Published May 2, 2007· Updated Apr 23, 2026

CVE-2007-2431

CVE-2007-2431

Description

Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web script via the _SERVER[SCRIPT_NAME] parameter.

Affected products

1
  • cpe:2.3:a:tecnick.com:tcexam:*:*:*:*:*:*:*:*
    Range: <=4.0.011

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.