TCExam SessionUserLang Remote PHP Code Execution Vulnerability
BID:23705
Info
TCExam SessionUserLang Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 23705 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2007 12:00AM |
| Updated: | May 02 2007 09:09PM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
TCExam TCExam 4.0.11 |
| Not Vulnerable: |
TCExam TCExam 4.1 |
Discussion
TCExam SessionUserLang Remote PHP Code Execution Vulnerability
TCExam is prone to an arbitrary PHP code-execution vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary malicious PHP code in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
TCExam 4.0.011 and prior versions are vulnerable.
TCExam is prone to an arbitrary PHP code-execution vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary malicious PHP code in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
TCExam 4.0.011 and prior versions are vulnerable.
Exploit / POC
TCExam SessionUserLang Remote PHP Code Execution Vulnerability
Attackers can use a browser to exploit this issue.
Sample exploit code has been provided:
Attackers can use a browser to exploit this issue.
Sample exploit code has been provided:
Solution / Fix
TCExam SessionUserLang Remote PHP Code Execution Vulnerability
Solution:
The vendor has released version 4.1.000, which addresses this issue. Please see the references for more information.
TCExam TCExam 4.0.11
Solution:
The vendor has released version 4.1.000, which addresses this issue. Please see the references for more information.
TCExam TCExam 4.0.11
-
TCExam tcexam_4_1_000.zip
http://downloads.sourceforge.net/tcexam/tcexam_4_1_000.zip?modtime=117 7956448&big_mirror=0
References
TCExam SessionUserLang Remote PHP Code Execution Vulnerability
References:
References:
- TCExam 4.1.000 new release with security fixes. (TCExam)
- TCExam Homepage (TCExam)