Claroline ScormExport.inc.PHP File Include Vulnerability
BID:17341
Info
Claroline ScormExport.inc.PHP File Include Vulnerability
| Bugtraq ID: | 17341 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2006 12:00AM |
| Updated: | May 08 2006 09:59PM |
| Credit: | Discovered by rgod <[email protected]>. |
| Vulnerable: |
Claroline Claroline 1.7.4 Claroline Claroline 1.7.2 Claroline Claroline 1.6 rc1 Claroline Claroline 1.6 beta Claroline Claroline 1.6 Claroline Claroline 1.5.4 Claroline Claroline 1.5.3 Claroline Claroline 1.5 |
| Not Vulnerable: |
Claroline Claroline 1.7.5 |
Discussion
Claroline ScormExport.inc.PHP File Include Vulnerability
Claroline is affected by a remote file-include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer or a remote location with the privileges of the webserver process. This may potentially facilitate unauthorized access.
Claroline is affected by a remote file-include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer or a remote location with the privileges of the webserver process. This may potentially facilitate unauthorized access.
Exploit / POC
Claroline ScormExport.inc.PHP File Include Vulnerability
This issue may be exploited through the use of a web browser.
Proof-of-concept code has been provided:
This issue may be exploited through the use of a web browser.
Proof-of-concept code has been provided:
Solution / Fix
Claroline ScormExport.inc.PHP File Include Vulnerability
Solution:
The vendor has released version 1.7.5 to address this and other issues.
Claroline Claroline 1.5
Claroline Claroline 1.5.3
Claroline Claroline 1.5.4
Claroline Claroline 1.6
Claroline Claroline 1.6 rc1
Claroline Claroline 1.6 beta
Claroline Claroline 1.7.2
Claroline Claroline 1.7.4
Solution:
The vendor has released version 1.7.5 to address this and other issues.
Claroline Claroline 1.5
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
Claroline Claroline 1.5.3
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
Claroline Claroline 1.5.4
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
Claroline Claroline 1.6
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
Claroline Claroline 1.6 rc1
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
Claroline Claroline 1.6 beta
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
Claroline Claroline 1.7.2
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
Claroline Claroline 1.7.4
-
Claroline claroline175.tar.gz
http://www.claroline.net/dlarea/claroline175.tar.gz
References
Claroline ScormExport.inc.PHP File Include Vulnerability
References:
References:
- Changelog 1.7.x (Claroline)
- Claroline Homepage (Claroline)