Перейти к содержимому
Noroxi

Записи ATutor

39 опубликованных записей вендора atutor.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 7,7 %
Pre-auth RCE
7
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

39 записей
  • CVE-2016-2555
    63На этой неделе

    SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands v

    КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %

    atutor · atutor13 апр. 2017 г.

  • CVE-2019-12169
    57В плане

    ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive t

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 72 %

    atutor · atutor3 июн. 2019 г.

  • CVE-2017-1000002
    48В плане

    ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting

    КритическаяCVSS 9,8Готовый эксплойтEPSS 31 %

    atutor · atutor17 июл. 2017 г.

  • CVE-2019-16114
    40В плане

    In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    atutor · atutor9 сент. 2019 г.

  • CVE-2017-1000004
    40В плане

    ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    atutor · atutor17 июл. 2017 г.

  • CVE-2014-9753
    40В плане

    confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logi

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    atutor · atutor11 февр. 2020 г.

  • CVE-2017-1000003
    40В плане

    ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resu

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    atutor · atutor17 июл. 2017 г.

  • CVE-2019-12170
    38Наблюдать

    ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.

    ВысокаяCVSS 8,8Proof of conceptEPSS 9 %

    atutor · atutor17 мая 2019 г.

  • CVE-2019-11446
    37Наблюдать

    An issue was discovered in ATutor through 2.2.4.

    ВысокаяCVSS 8,8Proof of conceptEPSS 8 %

    atutor · atutor22 апр. 2019 г.

  • CVE-2016-2539
    36Наблюдать

    Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authenti

    ВысокаяCVSS 8,8Proof of conceptEPSS 4 %

    atutor · atutor7 февр. 2017 г.

  • CVE-2020-10557
    35Наблюдать

    An issue was discovered in AContent through 1.4.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    atutor · acontent16 мар. 2020 г.

  • CVE-2015-1583
    35Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrato

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    atutor · atutor2 мар. 2020 г.

  • CVE-2012-5167
    31Наблюдать

    Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1)

    ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

    atutor · acontent22 окт. 2012 г.

  • CVE-2012-5168
    31Наблюдать

    ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/i

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    atutor · acontent22 окт. 2012 г.

  • CVE-2016-10400
    31Наблюдать

    Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    atutor · atutor22 июл. 2017 г.

  • CVE-2021-43498
    30Наблюдать

    An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTT

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    atutor · atutor8 апр. 2022 г.

  • CVE-2009-4945
    30Наблюдать

    AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via request

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    atutor · acollab22 июл. 2010 г.

  • CVE-2012-5453
    27Наблюдать

    SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arb

    СредняяCVSS 6,5Proof of conceptEPSS 3 %

    atutor · acontent22 окт. 2012 г.

  • CVE-2008-3368
    27Наблюдать

    PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrat

    СредняяCVSS 6,5Proof of conceptEPSS 3 %

    atutor · atutor30 июл. 2008 г.

  • CVE-2014-9752
    27Наблюдать

    Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    atutor · atutor16 нояб. 2015 г.

  • CVE-2015-7712
    27Наблюдать

    Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated user

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    atutor · atutor16 нояб. 2015 г.

  • CVE-2012-5454
    27Наблюдать

    user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to m

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    atutor · acontent22 окт. 2012 г.

  • CVE-2015-7711
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script o

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    atutor · atutor31 авг. 2017 г.

  • CVE-2023-27008
    24Наблюдать

    A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to i

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    atutor · atutor28 мар. 2023 г.

  • CVE-2019-7172
    24Наблюдать

    A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field t

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    atutor · atutor29 янв. 2019 г.