CVE-2008-3368: Code Injection
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3368?
CVE-2008-3368 is considered to have a high severity due to its remote file inclusion vulnerability that can lead to arbitrary PHP code execution.
How do I fix CVE-2008-3368?
To fix CVE-2008-3368, update your ATutor installation to version 1.6.2 or later, which includes a patch for this vulnerability.
What software versions are affected by CVE-2008-3368?
CVE-2008-3368 affects ATutor versions 1.6.1 pl1 and earlier, including versions 0.9.6 through 1.6.
What impact does CVE-2008-3368 have on my system?
The impact of CVE-2008-3368 includes the potential for remote authenticated attackers to execute malicious PHP code on the affected server.
Who is primarily affected by CVE-2008-3368?
Primarily, remote authenticated administrators using vulnerable versions of ATutor are at risk from CVE-2008-3368.