PT-2012-5978 · Atutor · Atutor Acontent

Published

2012-10-22

·

Updated

2013-04-11

·

CVE-2012-5453

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ATutor AContent versions 1.2-1
Description A SQL injection issue exists, allowing remote authenticated users to execute arbitrary SQL commands via the field parameter in the user/index inline editor submit.php file. This issue is a result of an incomplete fix for a previous security problem.
Recommendations For ATutor AContent versions 1.2-1, consider restricting access to the user/index inline editor submit.php file until a proper fix is applied, and avoid using the field parameter in this context to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5453

Affected Products

Atutor Acontent