7.5
CVSSv2

CVE-2006-3662

Published: 18/07/2006 Updated: 11/04/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote malicious users to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL injection vulnerability is not possible." However, the relevant source code suggests that this issue may be legitimate, and the parameter is cleansed in 1.5.3.1

Vulnerable Product Search on Vulmon Subscribe to Product

adaptive technology resource centre atutor 1.5.3

Vendor Advisories

Debian Bug report logs - #351639 netpbm: [CVE-2005-3632, CVE-2005-3662] multiple buffer overflows in pnmtopng Package: netpbm; Maintainer for netpbm is Andreas Barth <aba@notsoarghorg>; Source for netpbm is src:netpbm-free (PTS, buildd, popcon) Reported by: Martin Pitt <mpitt@debianorg> Date: Mon, 6 Feb 2006 11: ...

Exploits

source: wwwsecurityfocuscom/bid/18898/info ATutor is prone to multiple input-validation vulnerabilities, including cross-site scripting and SQL-injection issues, because the application fails to properly sanitize user-supplied input A successful exploit of these vulnerabilities could allow an attacker to compromise the application, acc ...