Multiple cross-site scripting (XSS) vulnerabilities in filemanager/previewtop.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML via the (1) pathext, (2) popup, (3) framed, or (4) file parameter.
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to coursecategory/indexinlineeditorsubmit.php or (2) user/indexinlineeditorsubmit.php; or (3) id parameter to user/userpassword.php.
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/indexinlineeditorsubmit.php or (2) coursecategory/indexinlineeditorsubmit.php.