Vulnerability Details CVE-2008-3368
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.2%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2008-3368
-
cpe:2.3:a:atutor:atutor:0.9.6
-
cpe:2.3:a:atutor:atutor:0.9.7
-
cpe:2.3:a:atutor:atutor:1.0
-
cpe:2.3:a:atutor:atutor:1.2.1
-
cpe:2.3:a:atutor:atutor:1.2.2
-
cpe:2.3:a:atutor:atutor:1.3
-
cpe:2.3:a:atutor:atutor:1.3.1
-
cpe:2.3:a:atutor:atutor:1.3.2
-
cpe:2.3:a:atutor:atutor:1.3.3
-
cpe:2.3:a:atutor:atutor:1.4
-
cpe:2.3:a:atutor:atutor:1.4.1
-
cpe:2.3:a:atutor:atutor:1.4.2
-
cpe:2.3:a:atutor:atutor:1.4.3
-
cpe:2.3:a:atutor:atutor:1.5.1
-
cpe:2.3:a:atutor:atutor:1.5.2
-
cpe:2.3:a:atutor:atutor:1.5.3
-
cpe:2.3:a:atutor:atutor:1.5.3.1
-
cpe:2.3:a:atutor:atutor:1.5.3.2
-
cpe:2.3:a:atutor:atutor:1.5.4
-
cpe:2.3:a:atutor:atutor:1.5.5
-
cpe:2.3:a:atutor:atutor:1.6
-
cpe:2.3:a:atutor:atutor:1.6.1