5.1
CVSSv2

CVE-2006-4844

Published: 19/09/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and previous versions, as used in Dokeos and possibly other products, allows remote malicious users to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dokeos open source learning and knowledge management tool 1.5

claroline claroline 1.7.5

dokeos open source learning and knowledge management tool 1.6 rc2

claroline claroline 1.7.4

claroline claroline 1.5.4

claroline claroline 1.2

claroline claroline

dokeos open source learning and knowledge management tool 1.5.3

claroline claroline 1.6 beta

dokeos open source learning and knowledge management tool 1.6.4

dokeos open source learning and knowledge management tool 1.5.5

dokeos open source learning and knowledge management tool 1.5.4

claroline claroline 1.7

claroline claroline 1.6 rc1

dokeos open source learning and knowledge management tool 1.6.5

claroline claroline 1.7.1

claroline claroline 1.3

claroline claroline 1.7.6

claroline claroline 1.4

claroline claroline 1.5

dokeos open source learning and knowledge management tool 1.4

claroline claroline 1.6

claroline claroline 1.5.3

claroline claroline 1.7.3

dokeos open source learning and knowledge management tool 1.6.4 p1

claroline claroline 1.7.2

Exploits

Claroline Arbitrary File Inclusion Vendor: Claroline Product: Claroline Version: <= 177 Website: wwwclarolinenet/ BID: 20056 CVE: CVE-2006-4844 OSVDB: 28827 SECUNIA: 21931 Description: Claroline is a popular online Open Source e-Learning application used to allow teachers or education organizations to create and administrate co ...