Directory Traversal and Code Execution Vulnerability in ATutor Course Component

Directory Traversal and Code Execution Vulnerability in ATutor Course Component

CVE-2017-1000002 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.

Learn more about our Web Application Penetration Testing UK.