CVE-2012-4601 Details
Description
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tecnick tcexam | <= 11.3.008 10.1.000 10.1.001 10.1.002 10.1.003 10.1.004 10.1.005 10.1.006 10.1.007 10.1.008 10.1.009 10.1.010 10.1.011 10.1.012 10.1.013 11.0.000 11.0.001 11.0.002 11.0.003 11.0.004 11.0.005 11.0.006 11.0.007 11.0.008 11.0.009 11.0.010 11.0.011 11.0.012 11.0.013 11.0.014 11.0.015 11.0.016 11.1.000 11.1.001 11.1.002 11.1.003 11.1.004 11.1.005 11.1.006 11.1.007 11.1.008 11.1.009 11.1.010 11.1.011 11.1.012 11.1.013 11.1.014 11.1.015 11.1.016 11.1.017 11.1.018 11.1.019 11.1.020 11.1.021 11.1.022 11.1.023 11.1.024 11.1.025 11.1.026 11.1.027 11.1.028 11.1.029 11.1.030 11.1.031 11.2.000 11.2.001 11.2.002 11.2.003 11.2.004 11.2.005 11.2.006 11.2.007 11.2.008 11.2.010 11.2.011 11.2.012 11.2.013 11.2.014 11.2.015 11.2.016 11.2.017 11.2.018 11.2.020 11.2.021 11.2.022 11.2.023 11.2.025 11.2.026 11.2.027 11.2.028 11.2.029 11.2.030 11.2.031 11.2.032 11.3.000 11.3.001 11.3.002 11.3.003 11.3.004 11.3.005 11.3.006 11.3.007 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Nov 26, 2012 | Initial Analysis | [email protected] |