Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.
Conclusion & alert: CVE-2005-2044 is rated High Exploit Risk (63.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.91%). Core evidence: 10 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.51% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 25832 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25833 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25829 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25830 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25834 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25828 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25827 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25826 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| 25831 | exploit_db | edb | 2005-06-16 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.40% | 2.91% | +1.51% |
| 2 | 2026-04-26 | 1.23% | 1.40% | +0.17% |
| 3 | 2025-08-14 | — | 1.23% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| adaptive_technology_resource_centre | atutor | 1.4.3 | cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.4.3:*:*:*:*:*:*:* |
| adaptive_technology_resource_centre | atutor | 1.5_rc_1 | cpe:2.3:a:adaptive_technology_resource_centre:atutor:1.5_rc_1:*:*:*:*:*:*:* |