CVE-2012-4237: SQL Injection
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subjectmoduleid parameter to (1) tceeditanswer.php or (2) tceeditquestion.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4237?
CVE-2012-4237 is classified as a high severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2012-4237?
To fix CVE-2012-4237, upgrade TCExam to version 11.3.008 or later to eliminate the SQL injection vulnerabilities.
What types of vulnerabilities does CVE-2012-4237 include?
CVE-2012-4237 includes multiple SQL injection vulnerabilities affecting tce_edit_answer.php and tce_edit_question.php.
Who is affected by CVE-2012-4237?
CVE-2012-4237 affects remote authenticated users with level 5 or greater permissions in TCExam versions before 11.3.008.
What is TCExam in relation to CVE-2012-4237?
TCExam is an online examination system that is impacted by CVE-2012-4237, which highlights security flaws that could be exploited.