Home/Product/atutor
Product

atutor

53 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-27008
all versions
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote atta
6.1MEDIUM
CVE-2021-43498
all versions
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_
7.5HIGH
CVE-2020-23341
<= 2.2.4
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute
6.1MEDIUM
CVE-2020-10557
<= 1.4
An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. T
8.8HIGH
CVE-2015-1583
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of ad
8.8HIGH
CVE-2014-9753
<= 2.2
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the
9.8CRITICAL
CVE-2019-16114
<= 2.2.4
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which a
9.8CRITICAL
CVE-2019-12169
>= 2.2.1 and <= 2.2.4
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP
8.8HIGH
CVE-2019-12170
<= 2.2.4
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This ma
8.8HIGH
CVE-2019-11446
<= 2.2.4
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege.
8.8HIGH
CVE-2019-7172
<= 2.2.4
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Na
6.1MEDIUM
CVE-2015-6521
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
5.4MEDIUM
CVE-2017-14981
<= 2.2.2
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data
5.4MEDIUM
CVE-2015-7711
<= 2.2
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary we
6.1MEDIUM
CVE-2016-10400
<= 2.2.1
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attac
7.5HIGH
CVE-2017-1000004
<= 2.2.1
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Cou
9.8CRITICAL
CVE-2017-1000003
<= 2.2.1
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application comp
9.8CRITICAL
CVE-2017-1000002
<= 2.2.1
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component
9.8CRITICAL
CVE-2016-2555
all versions
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL
9.8CRITICAL
CVE-2017-6483
<= 2.2.2
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtrati
6.1MEDIUM
CVE-2016-2539
<= 2.2.1
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack th
8.8HIGH
CVE-2015-7712
<= 2.2
Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenti
CVE-2014-9752
<= 2.2
Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote auth
CVE-2014-2091
all versions
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated
CVE-2012-6528
<= 2.0
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or
CVE-2012-5454
all versions
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated
CVE-2012-5453
all versions
SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to e
CVE-2012-5169
<= 1.2
Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote a
CVE-2012-5168
<= 1.2
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to
CVE-2012-5167
<= 1.2
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands vi
CVE-2011-3706
all versions
ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installa
CVE-2010-3455
all versions
Cross-site scripting (XSS) vulnerability in index.php in AChecker 1.0 allows remote attackers to inject arbitrary web script or HT
CVE-2009-4945
all versions
AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access v
CVE-2009-4944
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATRC ACollab 1.2 allow remote attackers to inject arbitrary web script or H
CVE-2009-4942
all versions
Cross-site request forgery (CSRF) vulnerability in ACollab 1.2 allows remote attackers to hijack the authentication of arbitrary u
CVE-2009-4941
all versions
Cross-site scripting (XSS) vulnerability in sign_in.php in ATRC ACollab 1.2 allows remote attackers to inject arbitrary web script
CVE-2010-0971
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges,
CVE-2008-3368
<= 1.6.1
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated a
CVE-2008-0828
<= 1.5.5
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.5 and earlier allow remote attackers to inject arbitrary web scr
CVE-2007-0381
all versions
Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified
CVE-2006-5734
all versions
Multiple PHP remote file inclusion vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary PHP code via a UR
CVE-2006-3996
<= 1.5.3.1
SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrar
CVE-2006-3821
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3 allow remote attackers to inject arbitrary web script or HTML
CVE-2006-3662
all versions
SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid par
CVE-2006-3484
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script o
CVE-2005-4155
all versions
registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in
CVE-2005-3404
all versions
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files vi
CVE-2005-3403
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary w
CVE-2005-2956
all versions
ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access contr
CVE-2005-2955
all versions
config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions
CVE-2005-2954
all versions
SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL c
CVE-2005-2649
all versions
Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) co
CVE-2005-2044
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web sc
threatengine.sh