Description
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-5336 Vulnerability (CVE-2006-5336)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (3.9.1)
PleskLin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-24044)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.9)
WordPress Plugin Dean's FCKEditor with pwwang's code Arbitrary File Upload (1.0.0)