Skip to content
Noroxi

Tecnick records

26 published records for vendor tecnick.

All records

26 records
  • An issue was discovered in TCPDF before 6.2.22.

    CriticalCVSS 9.8Proof of conceptEPSS 26%

    tecnick · tcpdfSep 14, 2018

  • When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ direc

    HighCVSS 7.5Proof of conceptEPSS 6%

    tecnick · tcexamJul 30, 2021

  • CVE-2009-4747
    31Monitor

    PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote atta

    HighCVSS 7.5Proof of conceptEPSS 3%

    tecnick · aiocpMar 26, 2010

  • CVE-2009-3220
    31Monitor

    PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute ar

    HighCVSS 7.5Proof of conceptEPSS 2%

    tecnick · aiocpSep 16, 2009

  • CVE-2010-2153
    29Monitor

    Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attacker

    MediumCVSS 6.8Proof of conceptEPSS 7%

    tecnick · tcexamJun 3, 2010

  • CVE-2020-5745
    29Monitor

    Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users i

    HighCVSS 7.4No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • CVE-2012-4237
    28Monitor

    Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exe

    MediumCVSS 6.8Proof of conceptEPSS 2%

    tecnick · tcexamAug 20, 2012

  • CVE-2023-6554
    26Monitor

    Missing authorisation in TCExam

    MediumCVSS 6.5No exploitEPSS 1%

    tecnick · tcexamJan 11, 2024

  • CVE-2012-4601
    24Monitor

    Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permi

    MediumCVSS 6.0No exploitEPSS 2%

    tecnick · tcexamNov 23, 2012

  • CVE-2020-5750
    24Monitor

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • CVE-2020-5748
    24Monitor

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.

    MediumCVSS 6.1No exploitEPSS 1%

    tecnick · tcexamAug 5, 2021

  • A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.

    MediumCVSS 6.1No exploitEPSS 1%

    tecnick · tcexamAug 5, 2021

  • TCExam before 14.1.2 has XSS via an ff_ or xl_ field.

    MediumCVSS 6.1No exploitEPSS 1%

    tecnick · tcexamJul 7, 2018

  • An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.

    MediumCVSS 5.3No exploitEPSS 1%

    tecnick · tcexamJul 30, 2021

  • CVE-2020-5747
    21Monitor

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    MediumCVSS 5.4No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • CVE-2020-5746
    21Monitor

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    MediumCVSS 5.4No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • CVE-2020-5749
    21Monitor

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    MediumCVSS 5.4No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • CVE-2020-5751
    21Monitor

    Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a

    MediumCVSS 5.4No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.

    MediumCVSS 5.4No exploitEPSS 1%

    tecnick · tcexamJul 30, 2021

  • A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.

    MediumCVSS 5.4No exploitEPSS 1%

    tecnick · tcexamJul 30, 2021

  • CVE-2011-3806
    20Monitor

    TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation

    MediumCVSS 5.0No exploitEPSS 1%

    tecnick · tcexamSep 23, 2011

  • CVE-2020-5744
    19Monitor

    Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

    MediumCVSS 4.9No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020

  • CVE-2012-4602
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow re

    MediumCVSS 4.3No exploitEPSS 2%

    tecnick · tcexamNov 23, 2012

  • CVE-2020-5743
    17Monitor

    Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don

    MediumCVSS 4.3No exploitEPSS 1%

    tecnick · tcexamMay 7, 2020