Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-7871
Disclosure Date: September 02, 2024 (last updated September 05, 2024)
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.
0
Attacker Value
Unknown
CVE-2024-43776
Disclosure Date: September 02, 2024 (last updated September 05, 2024)
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
0
Attacker Value
Unknown
CVE-2024-43775
Disclosure Date: September 02, 2024 (last updated September 05, 2024)
SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.
0
Attacker Value
Unknown
CVE-2024-43774
Disclosure Date: September 02, 2024 (last updated September 05, 2024)
SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.
0
Attacker Value
Unknown
CVE-2024-43773
Disclosure Date: September 02, 2024 (last updated September 05, 2024)
SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.
0
Attacker Value
Unknown
CVE-2024-43772
Disclosure Date: September 02, 2024 (last updated September 05, 2024)
SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.
0
Attacker Value
Unknown
CVE-2021-42336
Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters.
0
Attacker Value
Unknown
CVE-2021-42335
Disclosure Date: October 15, 2021 (last updated February 23, 2025)
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
0
Attacker Value
Unknown
CVE-2021-42334
Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions.
0
Attacker Value
Unknown
CVE-2021-42333
Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions.
0