CVE-2016-2555: SQL Injection
Published Apr 13, 2017
·Updated
SQL injection vulnerability in include/lib/mysqlconnect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
Affected Software
1 affected component
ATutor ATutor=2.2.1
Remediation
Event History
Apr 13, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-2555?
CVE-2016-2555 is classified as a critical severity vulnerability due to its ability to allow remote SQL execution.
2
How do I fix CVE-2016-2555?
To fix CVE-2016-2555, you should upgrade ATutor to the latest version that addresses this vulnerability.
3
What type of attack does CVE-2016-2555 enable?
CVE-2016-2555 enables attackers to perform SQL injection, potentially leading to unauthorized data access or manipulation.
4
Which component of ATutor is affected by CVE-2016-2555?
CVE-2016-2555 affects the mysql_connect.inc.php file in the ATutor 2.2.1 version.
5
Can CVE-2016-2555 affect user data security?
Yes, CVE-2016-2555 poses a significant risk to user data security as it allows attackers to execute arbitrary SQL commands.