Show filters
40 Total Results
Displaying 11-20 of 40
Sort by:
Attacker Value
Unknown
CVE-2022-24953
Disclosure Date: February 17, 2022 (last updated October 07, 2023)
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.
0
Attacker Value
Unknown
CVE-2021-29377
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.
0
Attacker Value
Unknown
CVE-2020-36154
Disclosure Date: January 04, 2021 (last updated February 22, 2025)
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative privileges via a Trojan horse application.
0
Attacker Value
Unknown
CVE-2020-11084
Disclosure Date: July 14, 2020 (last updated February 21, 2025)
In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the PC.
0
Attacker Value
Unknown
CVE-2014-1454
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input
0
Attacker Value
Unknown
CVE-2018-12989
Disclosure Date: August 03, 2018 (last updated November 27, 2024)
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2018-7539
Disclosure Date: April 17, 2018 (last updated November 26, 2024)
On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../../../../../../../../../../../../etc/passwd) to the web server (fuzzd/0.1.1) running the Maintenance Center on port TCP/8088. This can lead to full compromise of the device.
0
Attacker Value
Unknown
CVE-2017-5677
Disclosure Date: February 06, 2017 (last updated November 26, 2024)
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.
0
Attacker Value
Unknown
CVE-2015-0972
Disclosure Date: June 23, 2015 (last updated October 05, 2023)
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.
0
Attacker Value
Unknown
CVE-2014-7371
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0