CVE-2017-1000002
CRITICALATutor <= 2.2.1 - Path Traversal and Code Execution via Course Component
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-1000002.
Includes Metasploit module exploits/linux/http/atutor_filemanager_traversal.
AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in ATutor 2.2.1, allowing remote code execution by uploading a malicious ZIP file. It also includes authentication bypass techniques via type juggling and TOCTOU vulnerabilities.
Description
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.
Exploits (1)
This Metasploit module exploits a directory traversal vulnerability in ATutor 2.2.1, allowing remote code execution by uploading a malicious ZIP file. It also includes authentication bypass techniques via type juggling and TOCTOU vulnerabilities.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H