Vulnerabilities > CVE-2005-2955 - Local Security vulnerability in Adaptive Technology Resource Centre Atutor 1.5.1

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.

Vulnerable Configurations

Part Description Count
Application
Adaptive_Technology_Resource_Centre
1