CVE-2012-4601

UnknownEPSS 1.56%

Last modified

CVE-2012-4601 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.. EPSS estimates a 1.56% chance of exploitation in the next 30 days.

Description

Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.

Metrics

EPSS Probability
1.56%

72.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TecnickTcexam<= 11.3.008
TecnickTcexam10.1.000
TecnickTcexam10.1.001
TecnickTcexam10.1.002
TecnickTcexam10.1.003
TecnickTcexam10.1.004
TecnickTcexam10.1.005
TecnickTcexam10.1.006
TecnickTcexam10.1.007
TecnickTcexam10.1.008
TecnickTcexam10.1.009
TecnickTcexam10.1.010
TecnickTcexam10.1.011
TecnickTcexam10.1.012
TecnickTcexam10.1.013
TecnickTcexam11.0.000
TecnickTcexam11.0.001
TecnickTcexam11.0.002
TecnickTcexam11.0.003
TecnickTcexam11.0.004
TecnickTcexam11.0.005
TecnickTcexam11.0.006
TecnickTcexam11.0.007
TecnickTcexam11.0.008
TecnickTcexam11.0.009
TecnickTcexam11.0.010
TecnickTcexam11.0.011
TecnickTcexam11.0.012
TecnickTcexam11.0.013
TecnickTcexam11.0.014
TecnickTcexam11.0.015
TecnickTcexam11.0.016
TecnickTcexam11.1.000
TecnickTcexam11.1.001
TecnickTcexam11.1.002
TecnickTcexam11.1.003
TecnickTcexam11.1.004
TecnickTcexam11.1.005
TecnickTcexam11.1.006
TecnickTcexam11.1.007
TecnickTcexam11.1.008
TecnickTcexam11.1.009
TecnickTcexam11.1.010
TecnickTcexam11.1.011
TecnickTcexam11.1.012
TecnickTcexam11.1.013
TecnickTcexam11.1.014
TecnickTcexam11.1.015
TecnickTcexam11.1.016
TecnickTcexam11.1.017

Showing 50 of 102 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-4601?
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.
How severe is CVE-2012-4601?
Severity scoring for CVE-2012-4601 is pending analysis. The EPSS model estimates a 1.56% probability of exploitation in the next 30 days.
How do I fix CVE-2012-4601?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-4601?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST