ATutor kayıtları
atutor üreticisine ait 39 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %7,7
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-264 Permissions, Privileges, and Access Controls2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
39 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2016-2555Silahlaştırılmış | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands vatutor · atutor · CWE-89 | Kritik9,8 | — | %79,6 | 13 Nis 2017 |
57Planlayın | CVE-2019-12169Silahlaştırılmış | ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive tatutor · atutor · CWE-22 | Yüksek8,8 | — | %72,2 | 3 Haz 2019 |
48Planlayın | CVE-2017-1000002Silahlaştırılmış | ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting atutor · atutor · CWE-22 | Kritik9,8 | — | %30,8 | 17 Tem 2017 |
40Planlayın | CVE-2019-16114İstismar yok | In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him atutor · atutor · CWE-863 | Kritik9,8 | — | %4,8 | 9 Eyl 2019 |
40Planlayın | CVE-2017-1000004İstismar yok | ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,atutor · atutor · CWE-89 | Kritik9,8 | — | %4,7 | 17 Tem 2017 |
40Planlayın | CVE-2014-9753İstismar yok | confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logiatutor · atutor · CWE-287 | Kritik9,8 | — | %2,9 | 11 Şub 2020 |
40Planlayın | CVE-2017-1000003İstismar yok | ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resuatutor · atutor · CWE-269 | Kritik9,8 | — | %2,3 | 17 Tem 2017 |
38İzleyin | CVE-2019-12170Kavram kanıtı | ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.atutor · atutor · CWE-434 | Yüksek8,8 | — | %8,6 | 17 May 2019 |
37İzleyin | CVE-2019-11446Kavram kanıtı | An issue was discovered in ATutor through 2.2.4.atutor · atutor · CWE-434 | Yüksek8,8 | — | %7,8 | 22 Nis 2019 |
36İzleyin | CVE-2016-2539Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentiatutor · atutor · CWE-352 | Yüksek8,8 | — | %4,3 | 7 Şub 2017 |
35İzleyin | CVE-2020-10557İstismar yok | An issue was discovered in AContent through 1.4.atutor · acontent · CWE-434 | Yüksek8,8 | — | %1,4 | 16 Mar 2020 |
35İzleyin | CVE-2015-1583İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administratoatutor · atutor · CWE-352 | Yüksek8,8 | — | %1,2 | 2 Mar 2020 |
31İzleyin | CVE-2012-5167Kavram kanıtı | Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) atutor · acontent · CWE-89 | Yüksek7,5 | — | %4,7 | 22 Eki 2012 |
31İzleyin | CVE-2012-5168İstismar yok | ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/iatutor · acontent · CWE-264 | Yüksek7,5 | — | %3,4 | 22 Eki 2012 |
31İzleyin | CVE-2016-10400İstismar yok | Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.atutor · atutor · CWE-22 | Yüksek7,5 | — | %1,9 | 22 Tem 2017 |
30İzleyin | CVE-2021-43498İstismar yok | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTatutor · atutor · CWE-640 | Yüksek7,5 | — | %1,6 | 8 Nis 2022 |
30İzleyin | CVE-2009-4945İstismar yok | AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via requestatutor · acollab · CWE-255 | Yüksek7,5 | — | %1,3 | 22 Tem 2010 |
27İzleyin | CVE-2012-5453Kavram kanıtı | SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbatutor · acontent · CWE-89 | Orta6,5 | — | %2,7 | 22 Eki 2012 |
27İzleyin | CVE-2008-3368Kavram kanıtı | PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administratatutor · atutor · CWE-94 | Orta6,5 | — | %2,7 | 30 Tem 2008 |
27İzleyin | CVE-2014-9752İstismar yok | Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated atutor · atutor | Orta6,5 | — | %2,1 | 16 Kas 2015 |
27İzleyin | CVE-2015-7712İstismar yok | Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated useratutor · atutor | Orta6,5 | — | %2,1 | 16 Kas 2015 |
27İzleyin | CVE-2012-5454İstismar yok | user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to matutor · acontent · CWE-264 | Orta6,5 | — | %2,0 | 22 Eki 2012 |
24İzleyin | CVE-2015-7711İstismar yok | Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script oatutor · atutor · CWE-79 | Orta6,1 | — | %1,6 | 31 Ağu 2017 |
24İzleyin | CVE-2023-27008Kavram kanıtı | A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to iatutor · atutor · CWE-79 | Orta6,1 | — | %1,5 | 28 Mar 2023 |
24İzleyin | CVE-2019-7172İstismar yok | A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field tatutor · atutor · CWE-79 | Orta6,1 | — | %0,9 | 29 Oca 2019 |
- CVE-2016-255563Bu hafta
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands v
KritikCVSS 9,8SilahlaştırılmışEPSS %80atutor · atutor13 Nis 2017
- CVE-2019-1216957Planlayın
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive t
YüksekCVSS 8,8SilahlaştırılmışEPSS %72atutor · atutor3 Haz 2019
- CVE-2017-100000248Planlayın
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting
KritikCVSS 9,8SilahlaştırılmışEPSS %31atutor · atutor17 Tem 2017
- CVE-2019-1611440Planlayın
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him
KritikCVSS 9,8İstismar yokEPSS %5atutor · atutor9 Eyl 2019
- CVE-2017-100000440Planlayın
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,
KritikCVSS 9,8İstismar yokEPSS %5atutor · atutor17 Tem 2017
- CVE-2014-975340Planlayın
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logi
KritikCVSS 9,8İstismar yokEPSS %3atutor · atutor11 Şub 2020
- CVE-2017-100000340Planlayın
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resu
KritikCVSS 9,8İstismar yokEPSS %2atutor · atutor17 Tem 2017
- CVE-2019-1217038İzleyin
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.
YüksekCVSS 8,8Kavram kanıtıEPSS %9atutor · atutor17 May 2019
- CVE-2019-1144637İzleyin
An issue was discovered in ATutor through 2.2.4.
YüksekCVSS 8,8Kavram kanıtıEPSS %8atutor · atutor22 Nis 2019
- CVE-2016-253936İzleyin
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authenti
YüksekCVSS 8,8Kavram kanıtıEPSS %4atutor · atutor7 Şub 2017
- CVE-2020-1055735İzleyin
An issue was discovered in AContent through 1.4.
YüksekCVSS 8,8İstismar yokEPSS %1atutor · acontent16 Mar 2020
- CVE-2015-158335İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrato
YüksekCVSS 8,8İstismar yokEPSS %1atutor · atutor2 Mar 2020
- CVE-2012-516731İzleyin
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1)
YüksekCVSS 7,5Kavram kanıtıEPSS %5atutor · acontent22 Eki 2012
- CVE-2012-516831İzleyin
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/i
YüksekCVSS 7,5İstismar yokEPSS %3atutor · acontent22 Eki 2012
- CVE-2016-1040031İzleyin
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.
YüksekCVSS 7,5İstismar yokEPSS %2atutor · atutor22 Tem 2017
- CVE-2021-4349830İzleyin
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTT
YüksekCVSS 7,5İstismar yokEPSS %2atutor · atutor8 Nis 2022
- CVE-2009-494530İzleyin
AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via request
YüksekCVSS 7,5İstismar yokEPSS %1atutor · acollab22 Tem 2010
- CVE-2012-545327İzleyin
SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arb
OrtaCVSS 6,5Kavram kanıtıEPSS %3atutor · acontent22 Eki 2012
- CVE-2008-336827İzleyin
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrat
OrtaCVSS 6,5Kavram kanıtıEPSS %3atutor · atutor30 Tem 2008
- CVE-2014-975227İzleyin
Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated
OrtaCVSS 6,5İstismar yokEPSS %2atutor · atutor16 Kas 2015
- CVE-2015-771227İzleyin
Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated user
OrtaCVSS 6,5İstismar yokEPSS %2atutor · atutor16 Kas 2015
- CVE-2012-545427İzleyin
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to m
OrtaCVSS 6,5İstismar yokEPSS %2atutor · acontent22 Eki 2012
- CVE-2015-771124İzleyin
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script o
OrtaCVSS 6,1İstismar yokEPSS %2atutor · atutor31 Ağu 2017
- CVE-2023-2700824İzleyin
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to i
OrtaCVSS 6,1Kavram kanıtıEPSS %1atutor · atutor28 Mar 2023
- CVE-2019-717224İzleyin
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field t
OrtaCVSS 6,1İstismar yokEPSS %1atutor · atutor29 Oca 2019