Pilotgroup develops a compact suite of web-facing e-learning and content-management platforms, including ELMS Pro, AllShareVideo, and eTraining, where vulnerabilities cluster around input-handling weaknesses such as cross-site scripting and SQL injection. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit tooling, reflecting the recurring application-layer validation issues endemic to web software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pilotgroup over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15969CRITICAL PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category. | Oct 29, 2017 | 9.8 | 43 | NO | YES |
CVE-2010-2354HIGH SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter. | Jun 21, 2010 | 7.5 | 29 | NO | YES |
CVE-2008-6117HIGH SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands via the poll_view_id parameter in a results action. | Feb 11, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5307HIGH SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter. NOTE: some of t | Dec 2, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5306HIGH SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: so | Dec 2, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4709HIGH SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter. | Oct 23, 2008 | 7.5 | 28 | NO | YES |
CVE-2010-2356MEDIUM Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter. | Jun 21, 2010 | 4.3 | 23 | NO | YES |
CVE-2010-2355MEDIUM Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: | Jun 21, 2010 | 4.3 | 22 | NO | YES |
CVE-2009-3513MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to cour | Oct 1, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pilotgroup.
Media articles that mention a CVE ID that affects a product developed by Pilotgroup — matched by CVE ID, not by vendor name.