Skip to main content

Vendor archive

tecnick CVEs

Beta · best-effort

26 CVEs tagged to vendor tecnick1 Critical, 4 High, 20 Medium, 1 Low, 0 Unrated.

CVE-2023-6554

Published Jan 11, 2024

When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20116

Published Aug 5, 2021

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validat…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20115

Published Aug 5, 2021

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated an…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20114

Published Jul 30, 2021

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20113

Published Jul 30, 2021

An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then w…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20112

Published Jul 30, 2021

A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20111

Published Jul 30, 2021

A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as te…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5751

Published May 7, 2020

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5750

Published May 7, 2020

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feat…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5749

Published May 7, 2020

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted group.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5748

Published May 7, 2020

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feat…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5747

Published May 7, 2020

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5746

Published May 7, 2020

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5745

Published May 7, 2020

Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5744

Published May 7, 2020

Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5743

Published May 7, 2020

Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4602

Published Nov 23, 2012

Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4601

Published Nov 23, 2012

Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL command…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4238

Published Aug 20, 2012

Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to injec…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4237

Published Aug 20, 2012

Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the sub…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3806

Published Sep 24, 2011

TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2153

Published Jun 3, 2010

Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploadin…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4747

Published Mar 26, 2010

PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2