6.8
CVSSv2

CVE-2005-1374

Published: 03/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 695
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 up to and including 1.6 Release Candidate 1, and possibly Dokeos, allow remote malicious users to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4) learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php, (7) userLog.php, (8) tool parameter to toolaccess_details.php, (9) data parameter to user_access_details.php, or (10) coursePath parameter to myagenda.php.

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline 1.5.3

claroline claroline 1.6_beta

claroline claroline 1.6_rc1

Exploits

source: wwwsecurityfocuscom/bid/13407/info Multiple remote input validation vulnerabilities affect Claroline e-Learning Application These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating dyn ...
source: wwwsecurityfocuscom/bid/13407/info Multiple remote input validation vulnerabilities affect Claroline e-Learning Application These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating d ...
source: wwwsecurityfocuscom/bid/13407/info Multiple remote input validation vulnerabilities affect Claroline e-Learning Application These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating dy ...