Записи ATutor
39 опубликованных записей вендора atutor.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 7,7 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-264 Permissions, Privileges, and Access Controls2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
39 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2016-2555Готовый эксплойт | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands vatutor · atutor · CWE-89 | Критическая9,8 | — | 79,6 % | 13 апр. 2017 г. |
57В плане | CVE-2019-12169Готовый эксплойт | ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive tatutor · atutor · CWE-22 | Высокая8,8 | — | 72,2 % | 3 июн. 2019 г. |
48В плане | CVE-2017-1000002Готовый эксплойт | ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting atutor · atutor · CWE-22 | Критическая9,8 | — | 30,8 % | 17 июл. 2017 г. |
40В плане | CVE-2019-16114Эксплойта нет | In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him atutor · atutor · CWE-863 | Критическая9,8 | — | 4,8 % | 9 сент. 2019 г. |
40В плане | CVE-2017-1000004Эксплойта нет | ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,atutor · atutor · CWE-89 | Критическая9,8 | — | 4,7 % | 17 июл. 2017 г. |
40В плане | CVE-2014-9753Эксплойта нет | confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logiatutor · atutor · CWE-287 | Критическая9,8 | — | 2,9 % | 11 февр. 2020 г. |
40В плане | CVE-2017-1000003Эксплойта нет | ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resuatutor · atutor · CWE-269 | Критическая9,8 | — | 2,3 % | 17 июл. 2017 г. |
38Наблюдать | CVE-2019-12170Proof of concept | ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.atutor · atutor · CWE-434 | Высокая8,8 | — | 8,6 % | 17 мая 2019 г. |
37Наблюдать | CVE-2019-11446Proof of concept | An issue was discovered in ATutor through 2.2.4.atutor · atutor · CWE-434 | Высокая8,8 | — | 7,8 % | 22 апр. 2019 г. |
36Наблюдать | CVE-2016-2539Proof of concept | Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentiatutor · atutor · CWE-352 | Высокая8,8 | — | 4,3 % | 7 февр. 2017 г. |
35Наблюдать | CVE-2020-10557Эксплойта нет | An issue was discovered in AContent through 1.4.atutor · acontent · CWE-434 | Высокая8,8 | — | 1,4 % | 16 мар. 2020 г. |
35Наблюдать | CVE-2015-1583Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administratoatutor · atutor · CWE-352 | Высокая8,8 | — | 1,2 % | 2 мар. 2020 г. |
31Наблюдать | CVE-2012-5167Proof of concept | Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) atutor · acontent · CWE-89 | Высокая7,5 | — | 4,7 % | 22 окт. 2012 г. |
31Наблюдать | CVE-2012-5168Эксплойта нет | ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/iatutor · acontent · CWE-264 | Высокая7,5 | — | 3,4 % | 22 окт. 2012 г. |
31Наблюдать | CVE-2016-10400Эксплойта нет | Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.atutor · atutor · CWE-22 | Высокая7,5 | — | 1,9 % | 22 июл. 2017 г. |
30Наблюдать | CVE-2021-43498Эксплойта нет | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTatutor · atutor · CWE-640 | Высокая7,5 | — | 1,6 % | 8 апр. 2022 г. |
30Наблюдать | CVE-2009-4945Эксплойта нет | AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via requestatutor · acollab · CWE-255 | Высокая7,5 | — | 1,3 % | 22 июл. 2010 г. |
27Наблюдать | CVE-2012-5453Proof of concept | SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbatutor · acontent · CWE-89 | Средняя6,5 | — | 2,7 % | 22 окт. 2012 г. |
27Наблюдать | CVE-2008-3368Proof of concept | PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administratatutor · atutor · CWE-94 | Средняя6,5 | — | 2,7 % | 30 июл. 2008 г. |
27Наблюдать | CVE-2014-9752Эксплойта нет | Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated atutor · atutor | Средняя6,5 | — | 2,1 % | 16 нояб. 2015 г. |
27Наблюдать | CVE-2015-7712Эксплойта нет | Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated useratutor · atutor | Средняя6,5 | — | 2,1 % | 16 нояб. 2015 г. |
27Наблюдать | CVE-2012-5454Эксплойта нет | user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to matutor · acontent · CWE-264 | Средняя6,5 | — | 2,0 % | 22 окт. 2012 г. |
24Наблюдать | CVE-2015-7711Эксплойта нет | Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script oatutor · atutor · CWE-79 | Средняя6,1 | — | 1,6 % | 31 авг. 2017 г. |
24Наблюдать | CVE-2023-27008Proof of concept | A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to iatutor · atutor · CWE-79 | Средняя6,1 | — | 1,5 % | 28 мар. 2023 г. |
24Наблюдать | CVE-2019-7172Эксплойта нет | A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field tatutor · atutor · CWE-79 | Средняя6,1 | — | 0,9 % | 29 янв. 2019 г. |
- CVE-2016-255563На этой неделе
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands v
КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %atutor · atutor13 апр. 2017 г.
- CVE-2019-1216957В плане
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive t
ВысокаяCVSS 8,8Готовый эксплойтEPSS 72 %atutor · atutor3 июн. 2019 г.
- CVE-2017-100000248В плане
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting
КритическаяCVSS 9,8Готовый эксплойтEPSS 31 %atutor · atutor17 июл. 2017 г.
- CVE-2019-1611440В плане
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %atutor · atutor9 сент. 2019 г.
- CVE-2017-100000440В плане
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %atutor · atutor17 июл. 2017 г.
- CVE-2014-975340В плане
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logi
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %atutor · atutor11 февр. 2020 г.
- CVE-2017-100000340В плане
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resu
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %atutor · atutor17 июл. 2017 г.
- CVE-2019-1217038Наблюдать
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %atutor · atutor17 мая 2019 г.
- CVE-2019-1144637Наблюдать
An issue was discovered in ATutor through 2.2.4.
ВысокаяCVSS 8,8Proof of conceptEPSS 8 %atutor · atutor22 апр. 2019 г.
- CVE-2016-253936Наблюдать
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authenti
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %atutor · atutor7 февр. 2017 г.
- CVE-2020-1055735Наблюдать
An issue was discovered in AContent through 1.4.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %atutor · acontent16 мар. 2020 г.
- CVE-2015-158335Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrato
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %atutor · atutor2 мар. 2020 г.
- CVE-2012-516731Наблюдать
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %atutor · acontent22 окт. 2012 г.
- CVE-2012-516831Наблюдать
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/i
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %atutor · acontent22 окт. 2012 г.
- CVE-2016-1040031Наблюдать
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %atutor · atutor22 июл. 2017 г.
- CVE-2021-4349830Наблюдать
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTT
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %atutor · atutor8 апр. 2022 г.
- CVE-2009-494530Наблюдать
AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via request
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %atutor · acollab22 июл. 2010 г.
- CVE-2012-545327Наблюдать
SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arb
СредняяCVSS 6,5Proof of conceptEPSS 3 %atutor · acontent22 окт. 2012 г.
- CVE-2008-336827Наблюдать
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrat
СредняяCVSS 6,5Proof of conceptEPSS 3 %atutor · atutor30 июл. 2008 г.
- CVE-2014-975227Наблюдать
Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated
СредняяCVSS 6,5Эксплойта нетEPSS 2 %atutor · atutor16 нояб. 2015 г.
- CVE-2015-771227Наблюдать
Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated user
СредняяCVSS 6,5Эксплойта нетEPSS 2 %atutor · atutor16 нояб. 2015 г.
- CVE-2012-545427Наблюдать
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to m
СредняяCVSS 6,5Эксплойта нетEPSS 2 %atutor · acontent22 окт. 2012 г.
- CVE-2015-771124Наблюдать
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script o
СредняяCVSS 6,1Эксплойта нетEPSS 2 %atutor · atutor31 авг. 2017 г.
- CVE-2023-2700824Наблюдать
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to i
СредняяCVSS 6,1Proof of conceptEPSS 1 %atutor · atutor28 мар. 2023 г.
- CVE-2019-717224Наблюдать
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field t
СредняяCVSS 6,1Эксплойта нетEPSS 1 %atutor · atutor29 янв. 2019 г.