Description
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2011-1470)
W3 Total Cache CVE-2019-6715 Vulnerability (CVE-2019-6715)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.10)
WordPress Plugin ALO EasyMail Newsletter Multiple Cross-Site Scripting Vulnerabilities (2.4.7)
WordPress Plugin WordPress Download Manager Cross-Site Request Forgery (2.9.60)