header-logo
Suggest Exploit
vendor:
ATutor
by:
7.5
CVSS
HIGH
Arbitrary PHP command execution, Local file include, Cross-site scripting (XSS)
CWE
Product Name: ATutor
Affected Version From: 1.5.1-pl1
Affected Version To: 1.5.1-pl1
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

ATutor Multiple Vulnerabilities

ATutor is prone to multiple vulnerabilities. These issues can allow remote attackers to execute arbitrary PHP commands and carry out local file include and cross-site scripting attacks.

Mitigation:

Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/15221/info
 
ATutor is prone to multiple vulnerabilities.
 
These issues can allow remote attackers to execute arbitrary PHP commands and carry out local file include and cross-site scripting attacks.
 
ATutor 1.5.1-pl1 and prior versions are affected. 

http://www.example.com/documentation/common/body_header.inc.php?section=[file]%00