Skip to content

fuzzlove/ATutor-2.2.4-Language-Exploit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 
 
 

Repository files navigation

ATutor 2.2.4 Arbitrary File Upload / RCE (CVE-2019-12169)

Description: ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.

Greetz: wetw0rk, offsec ^^

Notes: This application is no longer being maintained so there is no fix for this issue.

update: if you wish to test this manually I have included the poc.zip for a better understanding.

About

ATutor 2.2.4 Arbitrary File Upload / RCE (CVE-2019-12169)

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages