3.5
CVSSv2

CVE-2007-4717

Published: 05/09/2007 Updated: 08/03/2011
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 365
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Claroline prior to 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUserSearch.php, and the (3) view parameter in admin/campusProblem.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline

Exploits

source: wwwsecurityfocuscom/bid/25521/info Claroline is prone to a local file-include vulnerability and multiple cross-site scripting vulnerabilities An attacker could exploit these issues to execute local script code in the context of the application and access sensitive data, which may aid in further attacksThe attacker may also ...
source: wwwsecurityfocuscom/bid/25521/info Claroline is prone to a local file-include vulnerability and multiple cross-site scripting vulnerabilities An attacker could exploit these issues to execute local script code in the context of the application and access sensitive data, which may aid in further attacksThe attacker may als ...
source: wwwsecurityfocuscom/bid/25521/info Claroline is prone to a local file-include vulnerability and multiple cross-site scripting vulnerabilities An attacker could exploit these issues to execute local script code in the context of the application and access sensitive data, which may aid in further attacksThe attacker may also be ...