CVE Vulnerabilities

CVE-2005-2955

Published: Sep 16, 2005 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.

Affected Software

Name Vendor Start Version End Version
Atutor Adaptive_technology_resource_centre 1.5.1 (including) 1.5.1 (including)

References