Atutor

Atutor

31 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 79.62%
  • Veröffentlicht 13.04.2017 14:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 05.03.2017 20:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php)...

Exploit
  • EPSS 4.25%
  • Veröffentlicht 07.02.2017 15:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving ...

Exploit
  • EPSS 2.06%
  • Veröffentlicht 16.11.2015 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated users with the AT_PRIV_GRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter.

  • EPSS 2.11%
  • Veröffentlicht 16.11.2015 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course,...

Exploit
  • EPSS 1.27%
  • Veröffentlicht 02.03.2014 17:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title parameter in an add_forum action. NOTE: the origina...

Exploit
  • EPSS 1.85%
  • Veröffentlicht 31.01.2013 05:44:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2) login.php, (3) search.php, (4) password_rem...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 23.09.2011 23:55:02
  • Zuletzt bearbeitet 16.06.2026 23:33:46

ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by users/tool_settings.inc.php and certain other files.

Exploit
  • EPSS 1.65%
  • Veröffentlicht 16.03.2010 19:00:00
  • Zuletzt bearbeitet 16.06.2026 23:17:14

Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type a...

  • EPSS 2.65%
  • Veröffentlicht 30.07.2008 17:41:00
  • Zuletzt bearbeitet 16.06.2026 22:55:41

PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.