CVE-2005-3404
ATutor 1.4.1-1.5.1-pl1 - Remote File Inclusion via Section Parameter Null Byte Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-3404. PoCs published by Andreas Sandblad.
AI-analyzed exploit summary The provided text describes a local file inclusion (LFI) vulnerability in ATutor 1.5.1-pl1 and prior versions, where an attacker can include arbitrary files via a null-byte termination in the 'section' parameter of the print.php script.
Description
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php.
Exploits (2)
The provided text describes a local file inclusion (LFI) vulnerability in ATutor 1.5.1-pl1 and prior versions, where an attacker can include arbitrary files via a null-byte termination in the 'section' parameter of the print.php script.
The provided text describes a local file inclusion (LFI) vulnerability in ATutor 1.5.1-pl1 and prior versions, where an attacker can include arbitrary files via a null-byte termination in the 'section' parameter. No actual exploit code is present.