CVE-2008-3368
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.
- Affected products
- Atutor
- Atutor
- ≤ 1.6.1, 0.9.6, 0.9.7, 1.0, 1.2.1, 1.2.2, 1.3, 1.3.1, 1.3.2, 1.3.3, 1.4, 1.4.1, 1.4.2, 1.4.3, 1.5.1, 1.5.2, 1.5.3, 1.5.3.1, 1.5.3.2, 1.5.4, 1.5.5, 1.6
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 2.6% (84th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2008-07-30
CVE-2008-3368 at NVD
1 known exploit for CVE-2008-3368
Proof-of-concept code and exploit modules indexed by Sploitus