Vulnerabilities > CVE-2006-3996 - SQL Injection vulnerability in ATutor
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters. Update to 1.5.3.2
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | ATutor <= 1.5.3.1 (links) Remote Blind SQL Injection Exploit. CVE-2006-3996. Webapps exploit for php platform |
file | exploits/php/webapps/2088.php |
id | EDB-ID:2088 |
last seen | 2016-01-31 |
modified | 2006-07-30 |
platform | php |
port | |
published | 2006-07-30 |
reporter | rgod |
source | https://www.exploit-db.com/download/2088/ |
title | ATutor <= 1.5.3.1 links Remote Blind SQL Injection Exploit |
type | webapps |
References
- http://atutor.ca/news.php#010806
- http://retrogod.altervista.org/atutor_1531_sql.html
- http://secunia.com/advisories/21308
- http://securityreason.com/securityalert/1330
- http://www.osvdb.org/27665
- http://www.securityfocus.com/archive/1/441711/100/0/threaded
- http://www.securityfocus.com/bid/19232
- http://www.vupen.com/english/advisories/2006/3074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28082
- https://www.exploit-db.com/exploits/2088