Looking for the vulnerability index of Invicti's legacy products?
ATutor Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3368) - Vulnerability Database

ATutor Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3368)

Description

PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.

References