İçeriğe atla
Noroxi

ATutor kayıtları

atutor üreticisine ait 39 yayımlanmış kayıt.

Tüm kayıtlar

39 kayıt
  • CVE-2016-2555
    63Bu hafta

    SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands v

    KritikCVSS 9,8SilahlaştırılmışEPSS %80

    atutor · atutor13 Nis 2017

  • CVE-2019-12169
    57Planlayın

    ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive t

    YüksekCVSS 8,8SilahlaştırılmışEPSS %72

    atutor · atutor3 Haz 2019

  • CVE-2017-1000002
    48Planlayın

    ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting

    KritikCVSS 9,8SilahlaştırılmışEPSS %31

    atutor · atutor17 Tem 2017

  • CVE-2019-16114
    40Planlayın

    In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him

    KritikCVSS 9,8İstismar yokEPSS %5

    atutor · atutor9 Eyl 2019

  • CVE-2017-1000004
    40Planlayın

    ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,

    KritikCVSS 9,8İstismar yokEPSS %5

    atutor · atutor17 Tem 2017

  • CVE-2014-9753
    40Planlayın

    confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logi

    KritikCVSS 9,8İstismar yokEPSS %3

    atutor · atutor11 Şub 2020

  • CVE-2017-1000003
    40Planlayın

    ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resu

    KritikCVSS 9,8İstismar yokEPSS %2

    atutor · atutor17 Tem 2017

  • CVE-2019-12170
    38İzleyin

    ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.

    YüksekCVSS 8,8Kavram kanıtıEPSS %9

    atutor · atutor17 May 2019

  • CVE-2019-11446
    37İzleyin

    An issue was discovered in ATutor through 2.2.4.

    YüksekCVSS 8,8Kavram kanıtıEPSS %8

    atutor · atutor22 Nis 2019

  • CVE-2016-2539
    36İzleyin

    Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authenti

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    atutor · atutor7 Şub 2017

  • CVE-2020-10557
    35İzleyin

    An issue was discovered in AContent through 1.4.

    YüksekCVSS 8,8İstismar yokEPSS %1

    atutor · acontent16 Mar 2020

  • CVE-2015-1583
    35İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrato

    YüksekCVSS 8,8İstismar yokEPSS %1

    atutor · atutor2 Mar 2020

  • CVE-2012-5167
    31İzleyin

    Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1)

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    atutor · acontent22 Eki 2012

  • CVE-2012-5168
    31İzleyin

    ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/i

    YüksekCVSS 7,5İstismar yokEPSS %3

    atutor · acontent22 Eki 2012

  • CVE-2016-10400
    31İzleyin

    Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.

    YüksekCVSS 7,5İstismar yokEPSS %2

    atutor · atutor22 Tem 2017

  • CVE-2021-43498
    30İzleyin

    An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTT

    YüksekCVSS 7,5İstismar yokEPSS %2

    atutor · atutor8 Nis 2022

  • CVE-2009-4945
    30İzleyin

    AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via request

    YüksekCVSS 7,5İstismar yokEPSS %1

    atutor · acollab22 Tem 2010

  • CVE-2012-5453
    27İzleyin

    SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arb

    OrtaCVSS 6,5Kavram kanıtıEPSS %3

    atutor · acontent22 Eki 2012

  • CVE-2008-3368
    27İzleyin

    PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrat

    OrtaCVSS 6,5Kavram kanıtıEPSS %3

    atutor · atutor30 Tem 2008

  • CVE-2014-9752
    27İzleyin

    Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated

    OrtaCVSS 6,5İstismar yokEPSS %2

    atutor · atutor16 Kas 2015

  • CVE-2015-7712
    27İzleyin

    Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated user

    OrtaCVSS 6,5İstismar yokEPSS %2

    atutor · atutor16 Kas 2015

  • CVE-2012-5454
    27İzleyin

    user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to m

    OrtaCVSS 6,5İstismar yokEPSS %2

    atutor · acontent22 Eki 2012

  • CVE-2015-7711
    24İzleyin

    Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script o

    OrtaCVSS 6,1İstismar yokEPSS %2

    atutor · atutor31 Ağu 2017

  • CVE-2023-27008
    24İzleyin

    A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to i

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    atutor · atutor28 Mar 2023

  • CVE-2019-7172
    24İzleyin

    A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field t

    OrtaCVSS 6,1İstismar yokEPSS %1

    atutor · atutor29 Oca 2019