Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2014-9753
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.017
EPSS Ranking
81.2%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
7.5
References
http://karmainsecurity.com/KIS-2015-06
http://seclists.org/fulldisclosure/2015/Nov/11
http://update.atutor.ca/patch/2_2/2_2-6/patch.xml
http://www.securityfocus.com/archive/1/archive/1/536835/100/0/threaded
https://github.com/atutor/ATutor/commit/950a0299954e69b8742cc1f1a632f564435d4d7d
http://karmainsecurity.com/KIS-2015-06
http://seclists.org/fulldisclosure/2015/Nov/11
http://update.atutor.ca/patch/2_2/2_2-6/patch.xml
http://www.securityfocus.com/archive/1/archive/1/536835/100/0/threaded
https://github.com/atutor/ATutor/commit/950a0299954e69b8742cc1f1a632f564435d4d7d
Products affected by CVE-2014-9753
Atutor
»
Atutor
»
Version:
0.9.6
cpe:2.3:a:atutor:atutor:0.9.6
Atutor
»
Atutor
»
Version:
0.9.7
cpe:2.3:a:atutor:atutor:0.9.7
Atutor
»
Atutor
»
Version:
1.0
cpe:2.3:a:atutor:atutor:1.0
Atutor
»
Atutor
»
Version:
1.2.1
cpe:2.3:a:atutor:atutor:1.2.1
Atutor
»
Atutor
»
Version:
1.2.2
cpe:2.3:a:atutor:atutor:1.2.2
Atutor
»
Atutor
»
Version:
1.3
cpe:2.3:a:atutor:atutor:1.3
Atutor
»
Atutor
»
Version:
1.3.1
cpe:2.3:a:atutor:atutor:1.3.1
Atutor
»
Atutor
»
Version:
1.3.2
cpe:2.3:a:atutor:atutor:1.3.2
Atutor
»
Atutor
»
Version:
1.3.3
cpe:2.3:a:atutor:atutor:1.3.3
Atutor
»
Atutor
»
Version:
1.4
cpe:2.3:a:atutor:atutor:1.4
Atutor
»
Atutor
»
Version:
1.4.1
cpe:2.3:a:atutor:atutor:1.4.1
Atutor
»
Atutor
»
Version:
1.4.2
cpe:2.3:a:atutor:atutor:1.4.2
Atutor
»
Atutor
»
Version:
1.4.3
cpe:2.3:a:atutor:atutor:1.4.3
Atutor
»
Atutor
»
Version:
1.5
cpe:2.3:a:atutor:atutor:1.5
Atutor
»
Atutor
»
Version:
1.5.1
cpe:2.3:a:atutor:atutor:1.5.1
Atutor
»
Atutor
»
Version:
1.5.2
cpe:2.3:a:atutor:atutor:1.5.2
Atutor
»
Atutor
»
Version:
1.5.3
cpe:2.3:a:atutor:atutor:1.5.3
Atutor
»
Atutor
»
Version:
1.5.3.1
cpe:2.3:a:atutor:atutor:1.5.3.1
Atutor
»
Atutor
»
Version:
1.5.3.2
cpe:2.3:a:atutor:atutor:1.5.3.2
Atutor
»
Atutor
»
Version:
1.5.3.3
cpe:2.3:a:atutor:atutor:1.5.3.3
Atutor
»
Atutor
»
Version:
1.5.4
cpe:2.3:a:atutor:atutor:1.5.4
Atutor
»
Atutor
»
Version:
1.5.5
cpe:2.3:a:atutor:atutor:1.5.5
Atutor
»
Atutor
»
Version:
1.6
cpe:2.3:a:atutor:atutor:1.6
Atutor
»
Atutor
»
Version:
1.6.1
cpe:2.3:a:atutor:atutor:1.6.1
Atutor
»
Atutor
»
Version:
1.6.2
cpe:2.3:a:atutor:atutor:1.6.2
Atutor
»
Atutor
»
Version:
1.6.3
cpe:2.3:a:atutor:atutor:1.6.3
Atutor
»
Atutor
»
Version:
1.6.4
cpe:2.3:a:atutor:atutor:1.6.4
Atutor
»
Atutor
»
Version:
2.0
cpe:2.3:a:atutor:atutor:2.0
Atutor
»
Atutor
»
Version:
2.0.1
cpe:2.3:a:atutor:atutor:2.0.1
Atutor
»
Atutor
»
Version:
2.0.2
cpe:2.3:a:atutor:atutor:2.0.2
Atutor
»
Atutor
»
Version:
2.0.3
cpe:2.3:a:atutor:atutor:2.0.3
Atutor
»
Atutor
»
Version:
2.1
cpe:2.3:a:atutor:atutor:2.1
Atutor
»
Atutor
»
Version:
2.1.1
cpe:2.3:a:atutor:atutor:2.1.1
Atutor
»
Atutor
»
Version:
2.2
cpe:2.3:a:atutor:atutor:2.2
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved