New User, Welcome!     Login

online learning

[DSECRG-08-031] Local File Include Vulnerability in Interact 2.4.1

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-31


Application:                    Interact E-Learning System      
Versions Affected:              2.4.1
Vendor URL:                     http://sourceforge.net/projects/cce-interact
Bug:                            Local File Include
Exploits:                       YES
Reported:                       03.07.2008

[DSECRG-08-015] Multiple Security Vulnerabilities in Dokeos 1.8.4

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-015


Application:                    Dokeos E-Learning System        
Versions Affected:              1.8.4
Vendor URL:                     http://dokeos.com
Bugs:                           Multiple SQL Injections,Multiple Blind SQL Injections,Multiple  XSS, etc.
Exploits:                       YES
Reported:                       25.01.2008

[DSECRG-08-029] Local File Include in Dokeos E-Learning System 1.8.5

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-029


Application:                    Dokeos E-Learning System        
Versions Affected:              1.8.5
Vendor URL:                     http://dokeos.com/
Bug:                            Local File Include
Exploits:                       YES
Reported:                       01.07.2008

Secunia Research: Adobe Shockwave Player "DEMX" Chunk Parsing Vulnerability

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

[HSC] Dokeos Multiple Cross-Site Scripting Vulnerabilities

[HSC] Dokeos Multiple Cross-Site Scripting Vulnerabilities

Dokeos is a learning management system used to manage e-learning. It's prone to 
cross-site scripting vulnerability. An attacker may leverage this issue to have 
arbitrary script code execute in the browser of an unsuspecting user in the 
context of the affected site. This may help the attacker steal cookie-based 
authentication credentials and launch other attacks. 




Remote File Inclusion Vulnerability

Found by Pepelux <pepelux[at]enye-sec.org>
eNYe-Sec - www.enye-sec.org

-- Description (by the author's page) --
eFront is an easy to use, visually attractive, SCORM compatible, eLearning
and Human Capital Development system. It is suitable for both company and
educational usage. The core eFront system is offered as open-source software
so you can download and start using it immediately. Check the functionality
matrix for different eFront editions.


Secunia Research: Adobe Shockwave Player 3D Parsing Memory Corruption

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability

3. *Vulnerability Description*

eFront [1] is an easy-to-use, open source and object-oriented
multilingual eLearning platform that can be used to build learning
communities, educate and retain the end-users.

eFront is vulnerable to local file inclusion vulnerability, which
allows an external remote attacker to upload an arbitrary file and
execute code on the vulnerable website learning platform.

Secunia Research: Adobe Shockwave Player Font Processing Buffer Overflow

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

Secunia Research: Adobe Shockwave Player Asset Entry Parsing Vulnerability

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

Secunia Research: Adobe Shockwave Player 3D Model Buffer Overflow

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

eFront Multiple Parameter Cross Site Scripting Vulnerabilities

I. BACKGROUND
---------------------

"eFront is a fully flexible eLearning system capable of fulfilling a wide
range of learning needs. With eFront you will discover new ways to perform
training tasks easier and faster, while keeping your people actively
engaged and in shape." from efrontlearning.net



VUPEN Security - Adobe Shockwave Player Multiple Code Execution Vulnerabilities

I. BACKGROUND --------------------- 
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to 
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION --------------------- 
VUPEN Vulnerability Research Team discovered four critical vulnerabilities 

Secunia Research: Adobe Shockwave Player 3D Model Two Integer Overflows

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

Secunia Research: Adobe Shockwave Player Signedness Error Vulnerability

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

Secunia Research: Adobe Shockwave Player Integer Overflow Vulnerability

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

Secunia Research: Adobe Shockwave Player "pamm" Chunk Parsing Vulnerability

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

VUPEN Security Research - Adobe Shockwave IML32 Multiple Code Execution Vulnerabilities (CVE-2010-0129)

"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to 
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION
---------------------

Call for Papers: The 6th International Conference for Internet Technology and Secured Transactions (ICITST-2011)!

* Infonomics
* Information Visualization
* Information Management
* Information Quality
* Technology-Enabled Information
* e-Learning
* e-Commerce
* e-Business
* e-Government
* e-Society
* System Design and Security for e-Services

VUPEN Security Research - Adobe Shockwave DIRAPI Multiple Code Execution Vulnerabilities (CVE-2010-1280)

"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to 
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION
---------------------

VUPEN Security Research - Adobe Shockwave rcsL Record Array Indexing Vulnerability (APSB11-19)

"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION
---------------------

VUPEN Security Research - Adobe Shockwave 3D Blocks Field Code Execution Vulnerability (CVE-2010-1283)

"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to 
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION
---------------------

Secunia Research: Adobe Shockwave Player Four Integer Overflow Vulnerabilities

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

Moodle 1.9.3 Remote Code Execution

I. BACKGROUND

From the Moodle web site: "Moodle is a course management system (CMS) -
a free, Open Source software package designed using sound pedagogical
principles, to help educators create effective online learning
communities".

II. DESCRIPTION

A Remote Code Execution exists in Moodle 1.9.3.

[DSECRG-08-030] Claroline 1.8.9 Multiple Security Vulnerabilities

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-030


Application:                    Claroline eLearning and eWorking platform
Versions Affected:              1.8.9
Vendor URL:                     http://www.claroline.net/
Bug:                            Multiple XSS, Phishing Through URL Redirection, Change User Password XSRF Vulnerability
Exploits:                       YES
Reported:                       04.07.2008

[DSECRG-08-032] Claroline 1.8.10 Multiple XSS Vulnerabilities

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-032


Application:                    Claroline eLearning and eWorking platform
Versions Affected:              1.8.10
Vendor URL:                     http://www.claroline.net/
Bug:                            Multiple Linked XSS
Exploits:                       YES
Reported:                       18.07.2008

VUPEN Security Research - Adobe Shockwave 3D Two Remote Code Execution Vulnerabilities (CVE-2010-1284)

"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to 
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION
---------------------

VUPEN Security Research - Adobe Shockwave DIRAPI LCTX Chunck Memory Corruption Vulnerability (APSB11-01)

"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to 
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION
---------------------

Secunia Research: Adobe Shockwave Player Integer Overflow Vulnerability

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 

Secunia Research: Adobe Shockwave Player Array Indexing Vulnerability

3) Vendor's Description of Software 

"Over 450 million Internet-enabled desktops have installed Adobe 
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment, 
interactive product demonstrations, and online learning applications."

Product Link:
http://www.adobe.com/products/shockwaveplayer/

====================================================================== 



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!