Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TCExam SessionUserLang 'tce_tmx.php' 远程PHP代码执行漏洞
Vulnerability Description
TCExam 的shared/code/tce_tmx.php文件允许远程攻击者通过放置文件内容和目录遍历操作到SessionUserLang cookie中,在cache/中创建任意的PHP文件。
CVSS Information
N/A
Vulnerability Type
N/A