CVE-2006-3996: SQL Injection
SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3996?
CVE-2006-3996 is considered to have a medium severity due to its SQL injection risk allowing authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2006-3996?
To fix CVE-2006-3996, update your ATutor installation to version 1.5.3.2 or later, which includes security patches.
Who is affected by CVE-2006-3996?
CVE-2006-3996 affects installations of ATutor version 1.5.3.1 and earlier, specifically those allowing remote authenticated users.
What methods can attackers use with CVE-2006-3996?
Attackers can exploit CVE-2006-3996 by manipulating the 'desc' or 'asc' parameters in SQL queries to execute unauthorized SQL commands.
When was CVE-2006-3996 reported?
CVE-2006-3996 was reported in August 2006, indicating a critical need for users of affected versions to secure their systems promptly.