CVE-2005-2649
ATutor 1.5.1 - Cross-Site Scripting via Course Parameter or Search Words
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2649. PoCs published by matrix_killer.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in ATutor by injecting arbitrary JavaScript code via the 'course' parameter in the login.php URL. The vulnerability arises due to insufficient input sanitization.
Description
Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in login.php or (2) words parameter in search.php.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ATutor by injecting arbitrary JavaScript code via the 'course' parameter in the login.php URL. The vulnerability arises due to insufficient input sanitization.