Show filters
40 Total Results
Displaying 11-20 of 40
Sort by:
Attacker Value
Unknown

CVE-2022-24953

Disclosure Date: February 17, 2022 (last updated October 07, 2023)
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.
Attacker Value
Unknown

CVE-2021-29377

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.
Attacker Value
Unknown

CVE-2020-36154

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative privileges via a Trojan horse application.
Attacker Value
Unknown

CVE-2020-11084

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the PC.
Attacker Value
Unknown

CVE-2014-1454

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input
Attacker Value
Unknown

CVE-2018-12989

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2018-7539

Disclosure Date: April 17, 2018 (last updated November 26, 2024)
On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../../../../../../../../../../../../etc/passwd) to the web server (fuzzd/0.1.1) running the Maintenance Center on port TCP/8088. This can lead to full compromise of the device.
0
Attacker Value
Unknown

CVE-2017-5677

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.
0
Attacker Value
Unknown

CVE-2015-0972

Disclosure Date: June 23, 2015 (last updated October 05, 2023)
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.
0
Attacker Value
Unknown

CVE-2014-7371

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0