Vulnerabilities > CVE-2005-2044 - Cross-Site Scripting vulnerability in ATutor

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
adaptive-technology-resource-centre
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.

Exploit-Db

  • descriptionATutor 1.4.3 inbox/index.php view Parameter XSS. CVE-2005-2044. Webapps exploit for php platform
    idEDB-ID:25831
    last seen2016-02-03
    modified2005-06-16
    published2005-06-16
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25831/
    titleATutor 1.4.3 inbox/index.php view Parameter XSS
  • descriptionATutor 1.4.3 directory.php Multiple Parameter XSS. CVE-2005-2044. Webapps exploit for php platform
    idEDB-ID:25834
    last seen2016-02-03
    modified2005-06-16
    published2005-06-16
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25834/
    titleATutor 1.4.3 - directory.php Multiple Parameter XSS
  • descriptionATutor 1.4.3 tile.php Multiple Parameter XSS. CVE-2005-2044. Webapps exploit for php platform
    idEDB-ID:25832
    last seen2016-02-03
    modified2005-06-16
    published2005-06-16
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25832/
    titleATutor 1.4.3 tile.php Multiple Parameter XSS
  • descriptionATutor 1.4.3 content.php cid Parameter XSS. CVE-2005-2044 . Webapps exploit for php platform
    idEDB-ID:25828
    last seen2016-02-03
    modified2005-06-16
    published2005-06-16
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25828/
    titleATutor 1.4.3 content.php cid Parameter XSS
  • descriptionATutor 1.4.3 contact.php subject Parameter XSS. CVE-2005-2044. Webapps exploit for php platform
    idEDB-ID:25827
    last seen2016-02-03
    modified2005-06-16
    published2005-06-16
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25827/
    titleATutor 1.4.3 contact.php subject Parameter XSS
  • descriptionATutor 1.4.3 send_message.php l Parameter XSS. CVE-2005-2044. Webapps exploit for php platform
    idEDB-ID:25829
    last seen2016-02-03
    modified2005-06-16
    published2005-06-16
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/25829/
    titleATutor 1.4.3 send_message.php l Parameter XSS