296,225
Total vulnerabilities in the database
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.
Software | From | Fixed in |
---|---|---|
chamilo / chamilo_lms | 1.9.0 | 1.9.0.x |
chamilo / chamilo_lms | 1.8.8.4 | 1.8.8.4.x |
chamilo / chamilo_lms | 1.8.7.1 | 1.8.7.1.x |
chamilo / chamilo_lms | 1.8.8.6 | 1.8.8.6.x |
chamilo / chamilo_lms | 1.8.7 | 1.8.7.x |
chamilo / chamilo_lms | - | 1.9.6.x |
chamilo / chamilo_lms | 1.9.4 | 1.9.4.x |
chamilo / chamilo_lms | 1.9.2 | 1.9.2.x |
chamilo / chamilo_lms | 1.8.6.2 | 1.8.6.2.x |
chamilo / chamilo_lms | 1.8.8.2 | 1.8.8.2.x |