Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2012-6515

Disclosure Date: January 24, 2013 (last updated October 05, 2023)
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2012-4269

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachment in a message.
0
Attacker Value
Unknown

CVE-2012-4270

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the subject box of a message.
0