Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2021-35966
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
0
Attacker Value
Unknown
CVE-2021-35967
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.
0
Attacker Value
Unknown
CVE-2021-35964
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.
0
Attacker Value
Unknown
CVE-2020-9298
Disclosure Date: August 28, 2020 (last updated February 22, 2025)
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
0
Attacker Value
Unknown
CVE-2013-4245
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
Orca has arbitrary code execution due to insecure Python module load
0
Attacker Value
Unknown
CVE-2015-0972
Disclosure Date: June 23, 2015 (last updated October 05, 2023)
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.
0
Attacker Value
Unknown
CVE-2009-3017
Disclosure Date: August 31, 2009 (last updated October 04, 2023)
Orca Browser 1.2 build 5 does not properly block data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header, (3) injecting a Location header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header; and does not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location HTTP response header or (6) specifying the content of a Location HTTP response header.
0
Attacker Value
Unknown
CVE-2009-2919
Disclosure Date: August 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.
0
Attacker Value
Unknown
CVE-2008-5167
Disclosure Date: November 19, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter.
0
Attacker Value
Unknown
CVE-2005-3941
Disclosure Date: December 01, 2005 (last updated February 22, 2025)
SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.
0