efrontlearning records
13 published records for vendor efrontlearning.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2010-1918Proof of concept | SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chefrontlearning · efront · CWE-89 | High7.5 | — | 1.2% | May 12, 2010 |
29Monitor | CVE-2010-1003Proof of concept | Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to includeefrontlearning · efront · CWE-22 | Medium6.8 | — | 5.0% | Mar 19, 2010 |
28Monitor | CVE-2008-7026Proof of concept | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arefrontlearning · efront · CWE-264 | Medium6.8 | — | 4.7% | Aug 21, 2009 |
28Monitor | CVE-2009-3660Proof of concept | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remoefrontlearning · efront · CWE-94 | Medium6.8 | — | 1.9% | Oct 11, 2009 |
26Monitor | CVE-2015-4461No exploit | Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via aefrontlearning · efront · CWE-22 | Medium6.5 | — | 1.2% | Feb 5, 2018 |
26Monitor | CVE-2015-4463No exploit | The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by apefrontlearning · efront · CWE-434 | Medium6.5 | — | 1.2% | Jul 25, 2017 |
26Monitor | CVE-2015-4462No exploit | Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read efrontlearning · efront · CWE-434 | Medium6.5 | — | 1.1% | Jul 25, 2017 |
25Monitor | CVE-2012-4269No exploit | Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file withefrontlearning · efront | Medium6.0 | — | 2.1% | Aug 13, 2012 |
20Monitor | CVE-2012-6515No exploit | eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in tefrontlearning · efront · CWE-200 | Medium5.0 | — | 1.5% | Jan 23, 2013 |
18Monitor | CVE-2014-4033Proof of concept | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to efrontlearning · efront · CWE-79 | Medium4.3 | — | 3.3% | Jun 11, 2014 |
17Monitor | CVE-2012-1048Proof of concept | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly otherefrontlearning · efront community \+\+ · CWE-79 | Medium4.3 | — | 1.5% | Feb 12, 2012 |
15Monitor | CVE-2013-7194Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated adminefrontlearning · efront · CWE-79 | Low3.5 | — | 2.6% | Dec 20, 2013 |
14Monitor | CVE-2012-4270No exploit | Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the sefrontlearning · efront · CWE-79 | Low3.5 | — | 1.0% | Aug 13, 2012 |
- CVE-2010-191830Monitor
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ch
HighCVSS 7.5Proof of conceptEPSS 1%efrontlearning · efrontMay 12, 2010
- CVE-2010-100329Monitor
Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include
MediumCVSS 6.8Proof of conceptEPSS 5%efrontlearning · efrontMar 19, 2010
- CVE-2008-702628Monitor
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute ar
MediumCVSS 6.8Proof of conceptEPSS 5%efrontlearning · efrontAug 21, 2009
- CVE-2009-366028Monitor
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remo
MediumCVSS 6.8Proof of conceptEPSS 2%efrontlearning · efrontOct 11, 2009
- CVE-2015-446126Monitor
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a
MediumCVSS 6.5No exploitEPSS 1%efrontlearning · efrontFeb 5, 2018
- CVE-2015-446326Monitor
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by ap
MediumCVSS 6.5No exploitEPSS 1%efrontlearning · efrontJul 25, 2017
- CVE-2015-446226Monitor
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read
MediumCVSS 6.5No exploitEPSS 1%efrontlearning · efrontJul 25, 2017
- CVE-2012-426925Monitor
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with
MediumCVSS 6.0No exploitEPSS 2%efrontlearning · efrontAug 13, 2012
- CVE-2012-651520Monitor
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in t
MediumCVSS 5.0No exploitEPSS 1%efrontlearning · efrontJan 23, 2013
- CVE-2014-403318Monitor
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to
MediumCVSS 4.3Proof of conceptEPSS 3%efrontlearning · efrontJun 11, 2014
- CVE-2012-104817Monitor
Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other
MediumCVSS 4.3Proof of conceptEPSS 1%efrontlearning · efront community \+\+Feb 12, 2012
- CVE-2013-719415Monitor
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated admin
LowCVSS 3.5Proof of conceptEPSS 3%efrontlearning · efrontDec 20, 2013
- CVE-2012-427014Monitor
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the s
LowCVSS 3.5No exploitEPSS 1%efrontlearning · efrontAug 13, 2012