Vulnerabilities > CVE-2006-3996 - SQL Injection vulnerability in ATutor

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
adaptive-technology-resource-centre
exploit available

Summary

SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters. Update to 1.5.3.2

Vulnerable Configurations

Part Description Count
Application
Adaptive_Technology_Resource_Centre
1

Exploit-Db

descriptionATutor <= 1.5.3.1 (links) Remote Blind SQL Injection Exploit. CVE-2006-3996. Webapps exploit for php platform
fileexploits/php/webapps/2088.php
idEDB-ID:2088
last seen2016-01-31
modified2006-07-30
platformphp
port
published2006-07-30
reporterrgod
sourcehttps://www.exploit-db.com/download/2088/
titleATutor <= 1.5.3.1 links Remote Blind SQL Injection Exploit
typewebapps