CVE-2006-3662
CVE-2006-3662
SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL injection vulnerability is not possible." However, the relevant source code suggests that this issue may be legitimate, and the parameter is cleansed in 1.5.3.1
Produtos afetados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/28192não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://archives.neohapsis.com/archives/bugtraq/2006-07/0096.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/27620http://www.osvdb.org/28188http://www.securityfocus.com/archive/1/439873/100/100/threadedhttp://www.securityfocus.com/archive/1/440837/100/100/threadedhttp://www.securityfocus.com/bid/18898