Vulnerabilities > CVE-2006-3662 - Unspecified vulnerability in Adaptive Technology Resource Centre Atutor 1.5.3

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL injection vulnerability is not possible." However, the relevant source code suggests that this issue may be legitimate, and the parameter is cleansed in 1.5.3.1

Vulnerable Configurations

Part Description Count
Application
Adaptive_Technology_Resource_Centre
1

Exploit-Db

descriptionATutor 1.5.3 Multiple Input Validation Vulnerabilities. CVE-2006-3662. Webapps exploit for php platform
idEDB-ID:28192
last seen2016-02-03
modified2006-07-08
published2006-07-08
reportersecurityconnection
sourcehttps://www.exploit-db.com/download/28192/
titleATutor 1.5.3 - Multiple Input Validation Vulnerabilities