NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46378 | CVE-2012-5168 | ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inline_editor_submit.php or (2) course_category/index_inline_editor_submit.php. | 2 | 7.5 | High | 2017-01-19 | 2013-04-10 | View | |
10278 | CVE-2011-3706 | ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by users/tool_settings.inc.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View | |
68620 | CVE-2005-2956 | ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
69067 | CVE-2005-3405 | ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
26519 | CVE-2015-5332 | Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature. | 2 | 7.1 | High | 2017-01-19 | 2016-03-02 | View |
Page 16223 of 17672, showing 5 records out of 88360 total, starting on record 81111, ending on 81115