Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2021-35966

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
0
Attacker Value
Unknown

CVE-2021-35967

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.
0
Attacker Value
Unknown

CVE-2021-35964

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.
Attacker Value
Unknown

CVE-2020-9298

Disclosure Date: August 28, 2020 (last updated February 22, 2025)
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Attacker Value
Unknown

CVE-2013-4245

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
Orca has arbitrary code execution due to insecure Python module load
Attacker Value
Unknown

CVE-2015-0972

Disclosure Date: June 23, 2015 (last updated October 05, 2023)
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.
0
Attacker Value
Unknown

CVE-2009-3017

Disclosure Date: August 31, 2009 (last updated October 04, 2023)
Orca Browser 1.2 build 5 does not properly block data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header, (3) injecting a Location header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header; and does not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location HTTP response header or (6) specifying the content of a Location HTTP response header.
0
Attacker Value
Unknown

CVE-2009-2919

Disclosure Date: August 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.
0
Attacker Value
Unknown

CVE-2008-5167

Disclosure Date: November 19, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter.
0
Attacker Value
Unknown

CVE-2005-3941

Disclosure Date: December 01, 2005 (last updated February 22, 2025)
SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.
0