Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atutor vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2011-3706
ATutor 2.0 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by users/tool_settings.inc.php and certain other files.
Atutor Atutor 2.0
7.5
CVSSv3
CVE-2021-43498
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
Atutor Atutor 2.2.4
9.8
CVSSv3
CVE-2016-2555
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote malicious users to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
Atutor Atutor 2.2.1
1 EDB exploit
12 Github repositories
NA
CVE-2010-0971
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/g...
Atutor Atutor 1.6.4
1 EDB exploit
8.8
CVSSv3
CVE-2015-1583
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote malicious users to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user acco...
Atutor Atutor 2.2
NA
CVE-2014-2091
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title parameter in an add_forum action. NOTE: the original disclosure also reported issu...
Atutor Atutor 2.1.1
1 EDB exploit
6.1
CVSSv3
CVE-2023-27008
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote malicious users to inject arbitrary web script or HTML via the token parameter.
Atutor Atutor 2.2.1
5.4
CVSSv3
CVE-2015-6521
Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
Atutor Atutor 2.2
NA
CVE-2006-3821
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3 allow remote malicious users to inject arbitrary web script or HTML via the (1) lang parameter in (a) index_list.php and (2) year, (3) month, and (4) day parameter in (b) registration.php.
Adaptive Technology Resource Centre Atutor 1.5.3
Adaptive Technology Resource Centre Atutor 1.5 Rc 1
Adaptive Technology Resource Centre Atutor 1.4.3
Adaptive Technology Resource Centre Atutor 1.5.1
Adaptive Technology Resource Centre Atutor 1.5.1 Pl1
Adaptive Technology Resource Centre Atutor 1.5.1 Pl2
Adaptive Technology Resource Centre Atutor 1.4.1
Adaptive Technology Resource Centre Atutor 1.4.2
NA
CVE-2012-5169
Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent prior to 1.2-2 allow remote malicious users to inject arbitrary web script or HTML via the (1) pathext, (2) popup, (3) framed, or (4) file parameter.
Atutor Acontent 1.2
Atutor Acontent
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-28254
CVE-2024-32515
CVE-2024-21338
validation
CVE-2024-32522
dos
CVE-2024-2101
CVE-2024-21107
elevation of privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »