Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ATutor-Instructor-Backup-Arbitrary-File — ATutor 2.2.4 'Backup' Remote Command Execution (CVE-2019-12170) | Kitploit
Tools/GitHubGitHub/fuzzlove/atutor-instructor-backup-arbitrary-file
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubfuzzlove/atutor-instructor-backup-arbitrary-file

ATutor-Instructor-Backup-Arbitrary-File

ATutor 2.2.4 'Backup' Remote Command Execution (CVE-2019-12170)

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
317 years agoNot yet reviewed

ATutor-Instructor-Backup-Exploit

  • Exploit Title: ATutor 2.2.4 'Backup' Remote Command Execution (CVE-2019-12170)
  • Google Dork: inurl:/ATutor/login.php
  • Date: 5/13/2019
  • Exploit Author: liquidsky (Joseph McPeters)
  • Vendor Homepage: https://atutor.github.io/
  • Software Link: https://sourceforge.net/projects/atutor/files/latest/download
  • Version: < 2.2.4 (Versions 2.2.4 and prior seem to be affected)
  • Tested on: Windows 7 with XAMPP / Linux 3.16.0-4-amd64 with version 2.2.4 and 2.2.1
  • Authors Site: http://incidentsecurity.com/atutor-2-2-4-backup-remote-command-execution/
  • CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12170

ATutor 2.2.4 is vulnerable to arbitrary file uploads via the backup function that may result in remote command execution.

First login with the instructor account and select a course:

  • #1 http://[atutor address]/atutor/bounce.php?course=1

Then navigate to "Manage"

  • #2 http://[atutor address]/atutor/tools/index.php

Next select Backups/Upload

  • #3 http://[atutor address]/atutor/mods/_core/backups/upload.php

From here a specially crafted backup zip file i.e "pwned_backup.zip" can be uploaded that will result in remote command execution.

The PoC arbitrary file can be found at: http://[atutor address]/atutor/content/1/pwned/poc.PhP

or

C:\xampp\htdocs\ATutor\content\1\pwned\poc.PhP

Note: The "1" in the address will change based on the course number and the "content" directory may be different. However by default the installation calls for the dir name to be "content". This has been tested on both linux/windows installations.

  • A copy of the PoC zip file (pwned_backup.zip) can be downloaded: https://github.com/fuzzlove/ATutor-Instructor-Backup-Arbitrary-File

Screenshots included to show exact steps to successfully reenact exploit.

Update: There is no fix for this issue ATutor is no longer being maintained. [5/22/19]

  • Directory traversal is also possible if the content directory is not in the webroot.

For more information on a directory traversal proof of concept check out: https://github.com/fuzzlove/ATutor-2.2.4-Language-Exploit/

root@kitploit:~
    CVE-2019-12170: https://github.com/fuzzlove/ATutor-Instructor-Backup-Arbitrary-File
    CVE-2019-12169: https://github.com/fuzzlove/ATutor-2.2.4-Language-Exploit
Download Tool