shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.
| Software | From | Fixed in |
|---|---|---|
| tecnick.com / tcexam | - | 4.0.011.x |