This exploit demonstrates multiple vulnerabilities in ATutor 2.0.2, including SQL injection, cross-site scripting (XSS), path disclosure, and HTTP response splitting. The PoC provides specific payloads and endpoints to exploit these issues.
Classification
Working Poc 90%
Attack Type
Sqli | Xss | Info Leak | Other
Complexity
Trivial
Reliability
Reliable
Target:ATutor 2.0.2 (build r10589)
No auth needed
Prerequisites:Access to the target web application