Back

CVE-2005-3405

ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability.

Published: Nov 1, 2005 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-9gc7-f279-pcx9

ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 8.07%

Top 6% most likely to be exploited

Threat Score 32.4 / 100

Data Sources

NVD EPSS GitHub