ATutor Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2008-3368 - Vulnerability Database

ATutor Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2008-3368

Medium
Reference: CVE-2008-3368
Title: ATutor Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.