ATutor Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2010-0971
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users with Instructor privileges to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php the (3) Type and (4) Title fields in tools/groups/create_manual.php and the (5) Title field in assignments/add_assignment.php. NOTE: some of these details are obtained from third party information.