Перейти к содержимому
Noroxi

Записи efrontlearning

13 опубликованных записей вендора efrontlearning.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

13 записей
  • CVE-2010-1918
    30Наблюдать

    SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ch

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    efrontlearning · efront12 мая 2010 г.

  • CVE-2010-1003
    29Наблюдать

    Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include

    СредняяCVSS 6,8Proof of conceptEPSS 5 %

    efrontlearning · efront19 мар. 2010 г.

  • CVE-2008-7026
    28Наблюдать

    Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute ar

    СредняяCVSS 6,8Proof of conceptEPSS 5 %

    efrontlearning · efront21 авг. 2009 г.

  • CVE-2009-3660
    28Наблюдать

    PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remo

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    efrontlearning · efront11 окт. 2009 г.

  • CVE-2015-4461
    26Наблюдать

    Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    efrontlearning · efront5 февр. 2018 г.

  • CVE-2015-4463
    26Наблюдать

    The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by ap

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    efrontlearning · efront25 июл. 2017 г.

  • CVE-2015-4462
    26Наблюдать

    Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    efrontlearning · efront25 июл. 2017 г.

  • CVE-2012-4269
    25Наблюдать

    Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with

    СредняяCVSS 6,0Эксплойта нетEPSS 2 %

    efrontlearning · efront13 авг. 2012 г.

  • CVE-2012-6515
    20Наблюдать

    eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in t

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    efrontlearning · efront23 янв. 2013 г.

  • CVE-2014-4033
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to

    СредняяCVSS 4,3Proof of conceptEPSS 3 %

    efrontlearning · efront11 июн. 2014 г.

  • CVE-2012-1048
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other

    СредняяCVSS 4,3Proof of conceptEPSS 1 %

    efrontlearning · efront community \+\+12 февр. 2012 г.

  • CVE-2013-7194
    15Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated admin

    НизкаяCVSS 3,5Proof of conceptEPSS 3 %

    efrontlearning · efront20 дек. 2013 г.

  • CVE-2012-4270
    14Наблюдать

    Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the s

    НизкаяCVSS 3,5Эксплойта нетEPSS 1 %

    efrontlearning · efront13 авг. 2012 г.