AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-2955

MEDIUM · CVSS 4.6 EPSS 0.78%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-09-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2005-2955
Severity
MEDIUM
CVSS
4.6
EPSS
0.78%

Original NVD Description

config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.