Adaptive Technology Resource Centre
Adaptive Technology Resource Centre Atutor: vulnerabilidades y CVE
Adaptive Technology Resource Centre Atutor tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2007-0381 | Alta (7.5) | 1.1% | — | 19 ene 2007 | Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. NOTE: CVE analysis suggests that the vendor fixed these issues. |
| CVE-2006-5734 | Alta (7.5) | 1.4% | — | 6 nov 2006 | Multiple PHP remote file inclusion vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) section parameter in (a) documentation/common/frame_toc.php and (b)… |
| CVE-2006-3996 | Media (6.5) | 1.8% | — | 5 ago 2006 | SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters. |
| CVE-2006-3821 | Media (4.3) | 1.4% | — | 25 jul 2006 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in (a) index_list.php and (2) year, (3) month, and (4) day… |
| CVE-2006-3662 | Alta (7.5) | 1.3% | — | 18 jul 2006 | SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL… |
| CVE-2006-3484 | Baja (2.6) | 2.7% | — | 10 jul 2006 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a)… |
| CVE-2005-4155 | Alta (7.5) | 2.7% | — | 11 dic 2005 | registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check. NOTE: it is possible… |
| CVE-2005-3403 | Media (4.3) | 1.9% | — | 1 nov 2005 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path… |
| CVE-2005-3404 | Alta (7.5) | 10% | — | 1 nov 2005 | Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2)… |
| CVE-2005-2956 | Media (5) | 2.9% | — | 16 sept 2005 | ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat… |
| CVE-2005-2955 | Media (4.6) | 0.78% | — | 16 sept 2005 | config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by… |
| CVE-2005-2954 | Alta (7.5) | 1.7% | — | 16 sept 2005 | SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field. |
| CVE-2005-2649 | Media (4.3) | 3.6% | — | 23 ago 2005 | Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in login.php or (2) words parameter in search.php. |
| CVE-2005-2044 | Media (4.3) | 2.9% | — | 16 jun 2005 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to… |