Unrated severityNVD Advisory· Published Oct 22, 2012· Updated Apr 29, 2026
CVE-2012-5167
CVE-2012-5167
Description
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index_inline_editor_submit.php or (2) user/index_inline_editor_submit.php; or (3) id parameter to user/user_password.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- update.atutor.ca/acontent/patch/1_2/nvdPatch
- archives.neohapsis.com/archives/bugtraq/2012-10/0095.htmlnvdExploit
- www.securityfocus.com/bid/56100nvdExploit
- www.htbridge.com/advisory/HTB23117nvdExploit
- secunia.com/advisories/51014nvdVendor Advisory
- secunia.com/advisories/51034nvdVendor Advisory
- osvdb.org/86424nvd
- osvdb.org/86425nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/79459nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/79460nvd
News mentions
0No linked articles in our index yet.