CVE-2010-2153: Medium severity Tecnick TCExam vulnerability
Unrestricted file upload vulnerability in admin/code/tcefunctionstcecodeeditor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in cache/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2153?
CVE-2010-2153 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2010-2153?
To fix CVE-2010-2153, upgrade to a patched version of TCExam that addresses the unrestricted file upload vulnerability.
What versions of TCExam are affected by CVE-2010-2153?
CVE-2010-2153 affects TCExam versions 10.1.006 and 10.1.007.
Can CVE-2010-2153 allow attackers to execute arbitrary code?
Yes, CVE-2010-2153 allows remote attackers to execute arbitrary code by uploading malicious files.
What is the attack vector for CVE-2010-2153?
The attack vector for CVE-2010-2153 involves uploading a file with an executable extension and accessing it directly from the cache.