6.8

CVE-2007-2431

Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web script via the _SERVER[SCRIPT_NAME] parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tecnick.ComTcexam Version <= 4.0.011
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.1% 0.913
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/25008
http://sourceforge.net/forum/forum.php?forum_id=690912
Patch
https://www.exploit-db.com/exploits/3816
http://www.attrition.org/pipermail/vim/2007-May/001572.html
http://www.securityfocus.com/bid/23704
https://exchange.xforce.ibmcloud.com/vulnerabilities/33957