Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2015-4461

Disclosure Date: February 05, 2018 (last updated November 26, 2024)
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.
0
Attacker Value
Unknown

CVE-2015-4462

Disclosure Date: July 25, 2017 (last updated November 26, 2024)
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.
0
Attacker Value
Unknown

CVE-2015-4463

Disclosure Date: July 25, 2017 (last updated November 26, 2024)
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.
0
Attacker Value
Unknown

CVE-2014-4033

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via the surname parameter to student.php.
0
Attacker Value
Unknown

CVE-2013-7194

Disclosure Date: December 21, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field.
0
Attacker Value
Unknown

CVE-2012-6515

Disclosure Date: January 24, 2013 (last updated October 05, 2023)
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2012-4269

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachment in a message.
0
Attacker Value
Unknown

CVE-2012-4270

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the subject box of a message.
0
Attacker Value
Unknown

CVE-2012-1048

Disclosure Date: February 12, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
0
Attacker Value
Unknown

CVE-2010-1918

Disclosure Date: May 12, 2010 (last updated October 04, 2023)
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter.
0