Skip to content
Noroxi

efrontlearning records

13 published records for vendor efrontlearning.

All records

13 records
  • CVE-2010-1918
    30Monitor

    SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ch

    HighCVSS 7.5Proof of conceptEPSS 1%

    efrontlearning · efrontMay 12, 2010

  • CVE-2010-1003
    29Monitor

    Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include

    MediumCVSS 6.8Proof of conceptEPSS 5%

    efrontlearning · efrontMar 19, 2010

  • CVE-2008-7026
    28Monitor

    Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute ar

    MediumCVSS 6.8Proof of conceptEPSS 5%

    efrontlearning · efrontAug 21, 2009

  • CVE-2009-3660
    28Monitor

    PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remo

    MediumCVSS 6.8Proof of conceptEPSS 2%

    efrontlearning · efrontOct 11, 2009

  • CVE-2015-4461
    26Monitor

    Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a

    MediumCVSS 6.5No exploitEPSS 1%

    efrontlearning · efrontFeb 5, 2018

  • CVE-2015-4463
    26Monitor

    The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by ap

    MediumCVSS 6.5No exploitEPSS 1%

    efrontlearning · efrontJul 25, 2017

  • CVE-2015-4462
    26Monitor

    Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read

    MediumCVSS 6.5No exploitEPSS 1%

    efrontlearning · efrontJul 25, 2017

  • CVE-2012-4269
    25Monitor

    Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with

    MediumCVSS 6.0No exploitEPSS 2%

    efrontlearning · efrontAug 13, 2012

  • CVE-2012-6515
    20Monitor

    eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in t

    MediumCVSS 5.0No exploitEPSS 1%

    efrontlearning · efrontJan 23, 2013

  • CVE-2014-4033
    18Monitor

    Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to

    MediumCVSS 4.3Proof of conceptEPSS 3%

    efrontlearning · efrontJun 11, 2014

  • CVE-2012-1048
    17Monitor

    Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other

    MediumCVSS 4.3Proof of conceptEPSS 1%

    efrontlearning · efront community \+\+Feb 12, 2012

  • CVE-2013-7194
    15Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated admin

    LowCVSS 3.5Proof of conceptEPSS 3%

    efrontlearning · efrontDec 20, 2013

  • CVE-2012-4270
    14Monitor

    Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the s

    LowCVSS 3.5No exploitEPSS 1%

    efrontlearning · efrontAug 13, 2012