Total vulnerabilities in the database
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php.
Software | From | Fixed in |
---|---|---|
adaptive_technology_resource_centre / atutor | 1.4.2 | 1.4.2.x |
adaptive_technology_resource_centre / atutor | 1.5.1 | 1.5.1.x |
adaptive_technology_resource_centre / atutor | 1.4.1 | 1.4.1.x |
adaptive_technology_resource_centre / atutor | 1.5.1_pl1 | 1.5.1_pl1.x |
adaptive_technology_resource_centre / atutor | 1.4.3 | 1.4.3.x |