Skip to content
Noroxi

ATutor records

39 published records for vendor atutor.

All records

39 records
  • CVE-2016-2555
    63This week

    SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands v

    CriticalCVSS 9.8WeaponizedEPSS 80%

    atutor · atutorApr 13, 2017

  • ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive t

    HighCVSS 8.8WeaponizedEPSS 72%

    atutor · atutorJun 3, 2019

  • ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting

    CriticalCVSS 9.8WeaponizedEPSS 31%

    atutor · atutorJul 17, 2017

  • In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him

    CriticalCVSS 9.8No exploitEPSS 5%

    atutor · atutorSep 9, 2019

  • ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,

    CriticalCVSS 9.8No exploitEPSS 5%

    atutor · atutorJul 17, 2017

  • confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logi

    CriticalCVSS 9.8No exploitEPSS 3%

    atutor · atutorFeb 11, 2020

  • ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resu

    CriticalCVSS 9.8No exploitEPSS 2%

    atutor · atutorJul 17, 2017

  • ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.

    HighCVSS 8.8Proof of conceptEPSS 9%

    atutor · atutorMay 17, 2019

  • An issue was discovered in ATutor through 2.2.4.

    HighCVSS 8.8Proof of conceptEPSS 8%

    atutor · atutorApr 22, 2019

  • CVE-2016-2539
    36Monitor

    Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authenti

    HighCVSS 8.8Proof of conceptEPSS 4%

    atutor · atutorFeb 7, 2017

  • An issue was discovered in AContent through 1.4.

    HighCVSS 8.8No exploitEPSS 1%

    atutor · acontentMar 16, 2020

  • CVE-2015-1583
    35Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrato

    HighCVSS 8.8No exploitEPSS 1%

    atutor · atutorMar 2, 2020

  • CVE-2012-5167
    31Monitor

    Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1)

    HighCVSS 7.5Proof of conceptEPSS 5%

    atutor · acontentOct 22, 2012

  • CVE-2012-5168
    31Monitor

    ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/i

    HighCVSS 7.5No exploitEPSS 3%

    atutor · acontentOct 22, 2012

  • Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.

    HighCVSS 7.5No exploitEPSS 2%

    atutor · atutorJul 22, 2017

  • An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTT

    HighCVSS 7.5No exploitEPSS 2%

    atutor · atutorApr 8, 2022

  • CVE-2009-4945
    30Monitor

    AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via request

    HighCVSS 7.5No exploitEPSS 1%

    atutor · acollabJul 22, 2010

  • CVE-2012-5453
    27Monitor

    SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arb

    MediumCVSS 6.5Proof of conceptEPSS 3%

    atutor · acontentOct 22, 2012

  • CVE-2008-3368
    27Monitor

    PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrat

    MediumCVSS 6.5Proof of conceptEPSS 3%

    atutor · atutorJul 30, 2008

  • CVE-2014-9752
    27Monitor

    Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated

    MediumCVSS 6.5No exploitEPSS 2%

    atutor · atutorNov 16, 2015

  • CVE-2015-7712
    27Monitor

    Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated user

    MediumCVSS 6.5No exploitEPSS 2%

    atutor · atutorNov 16, 2015

  • CVE-2012-5454
    27Monitor

    user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to m

    MediumCVSS 6.5No exploitEPSS 2%

    atutor · acontentOct 22, 2012

  • CVE-2015-7711
    24Monitor

    Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script o

    MediumCVSS 6.1No exploitEPSS 2%

    atutor · atutorAug 31, 2017

  • A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to i

    MediumCVSS 6.1Proof of conceptEPSS 1%

    atutor · atutorMar 28, 2023

  • CVE-2019-7172
    24Monitor

    A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field t

    MediumCVSS 6.1No exploitEPSS 1%

    atutor · atutorJan 29, 2019