Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
claroline claroline 1.7.2 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-1594
Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and previous versions allow remote malicious users to use ".." (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.ph...
Claroline Claroline 1.5.4
Claroline Claroline 1.6 Beta
Claroline Claroline 1.6 Rc1
Claroline Claroline 1.5
Claroline Claroline 1.6
Claroline Claroline 1.5.3
Claroline Claroline
Claroline Claroline 1.7.2
4.3
CVSSv2
CVE-2006-1595
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and previous versions allows remote malicious users to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.
Claroline Claroline 1.5.4
Claroline Claroline 1.6 Beta
Claroline Claroline 1.6 Rc1
Claroline Claroline 1.5
Claroline Claroline 1.6
Claroline Claroline 1.5.3
Claroline Claroline
Claroline Claroline 1.7.2
2 EDB exploits
7.5
CVSSv2
CVE-2006-1596
PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and previous versions allows remote malicious users to execute arbitrary PHP code via the includePath parameter.
Claroline Claroline 1.7.4
Claroline Claroline 1.5.4
Claroline Claroline 1.6 Beta
Claroline Claroline 1.6 Rc1
Claroline Claroline 1.5
Claroline Claroline 1.6
Claroline Claroline 1.5.3
Claroline Claroline 1.7.2
10
CVSSv2
CVE-2006-0411
claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote malicious users to hijack sessions and possibly gain administrative privileges.
Claroline Claroline 1.7.2
7.5
CVSSv2
CVE-2006-5256
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the includePath parameter.
Claroline Claroline 1.7.5
Claroline Claroline 1.7.4
Claroline Claroline 1.5.4
Claroline Claroline 1.2
Claroline Claroline 1.6 Beta
Claroline Claroline 1.7
Claroline Claroline 1.6 Rc1
Claroline Claroline 1.7.1
Claroline Claroline 1.3
Claroline Claroline 1.7.6
Claroline Claroline 1.7.7
Claroline Claroline
Claroline Claroline 1.4
Claroline Claroline 1.5
Claroline Claroline 1.6
Claroline Claroline 1.5.3
Claroline Claroline 1.7.3
Claroline Claroline 1.7.2
1 EDB exploit
4.3
CVSSv2
CVE-2008-3260
Multiple cross-site scripting (XSS) vulnerabilities in Claroline prior to 1.8.10 allow remote malicious users to inject arbitrary web script or HTML via (1) the cwd parameter in a rqMkHtml action to document/rqmkhtml.php, or the query string to (2) announcements/announcements.php...
Claroline Claroline 1.8.1
Claroline Claroline 1.7.5
Claroline Claroline 1.8.2
Claroline Claroline 1.8.4
Claroline Claroline 1.7.4
Claroline Claroline 1.5.4
Claroline Claroline 1.2
Claroline Claroline
Claroline Claroline 1.6 Beta
Claroline Claroline 1.8.7
Claroline Claroline 1.8.8
Claroline Claroline 1.7
Claroline Claroline 1.6 Rc1
Claroline Claroline 1.7.1
Claroline Claroline 1.3
Claroline Claroline 1.7.6
Claroline Claroline 1.7.7
Claroline Claroline 1.4
Claroline Claroline 1.5
Claroline Claroline 1.8.5
Claroline Claroline 1.6
Claroline Claroline 1.8.6
12 EDB exploits
4.3
CVSSv2
CVE-2008-3261
Open redirect vulnerability in claroline/redirector.php in Claroline prior to 1.8.10 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
Claroline Claroline 1.8.1
Claroline Claroline 1.7.5
Claroline Claroline 1.8.2
Claroline Claroline 1.8.4
Claroline Claroline 1.7.4
Claroline Claroline 1.5.4
Claroline Claroline 1.2
Claroline Claroline
Claroline Claroline 1.6 Beta
Claroline Claroline 1.8.7
Claroline Claroline 1.8.8
Claroline Claroline 1.7
Claroline Claroline 1.6 Rc1
Claroline Claroline 1.7.1
Claroline Claroline 1.3
Claroline Claroline 1.7.6
Claroline Claroline 1.7.7
Claroline Claroline 1.4
Claroline Claroline 1.5
Claroline Claroline 1.8.5
Claroline Claroline 1.6
Claroline Claroline 1.8.6
1 EDB exploit
5.8
CVSSv2
CVE-2008-3262
Cross-site request forgery (CSRF) vulnerability in Claroline prior to 1.8.10 allows remote malicious users to change passwords, related to lack of a requirement for the previous password.
Claroline Claroline 1.8.1
Claroline Claroline 1.7.5
Claroline Claroline 1.8.2
Claroline Claroline 1.8.4
Claroline Claroline 1.7.4
Claroline Claroline 1.5.4
Claroline Claroline 1.2
Claroline Claroline
Claroline Claroline 1.6 Beta
Claroline Claroline 1.8.7
Claroline Claroline 1.8.8
Claroline Claroline 1.7
Claroline Claroline 1.6 Rc1
Claroline Claroline 1.7.1
Claroline Claroline 1.3
Claroline Claroline 1.7.6
Claroline Claroline 1.7.7
Claroline Claroline 1.4
Claroline Claroline 1.5
Claroline Claroline 1.8.5
Claroline Claroline 1.6
Claroline Claroline 1.8.6
6.8
CVSSv2
CVE-2006-2284
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote malicious users to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and the (2) claro_CasLibPath parameter in casProcess.inc.php.
Claroline Claroline 1.7.5
Dokeos Dokeos 1.6 Rc2
Claroline Claroline 1.7.4
Claroline Claroline 1.5.4
Claroline Claroline 1.6 Beta
Dokeos Dokeos 1.6.4
Dokeos Dokeos 1.5.5
Dokeos Dokeos 1.4
Dokeos Dokeos 1.5
Claroline Claroline 1.6 Rc1
Dokeos Dokeos 1.5.3
Claroline Claroline 1.5
Dokeos Dokeos 1.5.4
Claroline Claroline 1.6
Claroline Claroline 1.5.3
Claroline Claroline 1.7.2
1 EDB exploit
5.1
CVSSv2
CVE-2006-4844
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and previous versions, as used in Dokeos and possibly other products, allows remote malicious users to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.
Dokeos Open Source Learning And Knowledge Management Tool 1.5
Claroline Claroline 1.7.5
Dokeos Open Source Learning And Knowledge Management Tool 1.6 Rc2
Claroline Claroline 1.7.4
Claroline Claroline 1.5.4
Claroline Claroline 1.2
Claroline Claroline
Dokeos Open Source Learning And Knowledge Management Tool 1.5.3
Claroline Claroline 1.6 Beta
Dokeos Open Source Learning And Knowledge Management Tool 1.6.4
Dokeos Open Source Learning And Knowledge Management Tool 1.5.5
Dokeos Open Source Learning And Knowledge Management Tool 1.5.4
Claroline Claroline 1.7
Claroline Claroline 1.6 Rc1
Dokeos Open Source Learning And Knowledge Management Tool 1.6.5
Claroline Claroline 1.7.1
Claroline Claroline 1.3
Claroline Claroline 1.7.6
Claroline Claroline 1.4
Claroline Claroline 1.5
Dokeos Open Source Learning And Knowledge Management Tool 1.4
Claroline Claroline 1.6
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4541
CVE-2024-3080
CVE-2024-4787
log injection
CVE-2024-5967
inject
CVE-2024-30078
CVE-2024-5899
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started