CVE-2006-3996
SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters.
- Affected products
- Atutor
- Adaptive Technology Resource Centre Atutor
- ≤ 1.5.3.1
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 1.7% (75th percentile)
- NVD status
- Modified
- Published
- 2006-08-05
CVE-2006-3996 at NVD
1 known exploit for CVE-2006-3996
Proof-of-concept code and exploit modules indexed by Sploitus