7.5
CVSSv2

CVE-2005-1375

Published: 03/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 770
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Claroline 1.5.3 up to and including 1.6 Release Candidate 1, and possibly Dokeos, allow remote malicious users to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline 1.5.3

claroline claroline 1.6_beta

claroline claroline 1.6_rc1

Exploits

<?php ############################################################################# # T r a p - S e t U n d e r g r o u n d H a c k i n g T e a m ############################################################################# # Vulnerable: Claroline E-Learning Application # # Exploit By : MH_p0rtal # # Discovered By: Sieg Fried # ##### ...
#!/usr/bin/perl # Claroline E-Learning Application Remote SQL Exploit # [K-C0d3r] # This tools and to consider only himself to educational purpose # Bug discovered by # Greetz to mZ, 2b TUBE, off, rikky, str0ke, x0n3-h4ck, MWC # [K-C0d3r] use IO::Socket; sub Usage { print STDERR "Usage: KCcol-xplpl <wwwvictimcom> <path/dir> <tar ...
source: wwwsecurityfocuscom/bid/13407/info Multiple remote input validation vulnerabilities affect Claroline e-Learning Application These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating ...
source: wwwsecurityfocuscom/bid/13407/info Multiple remote input validation vulnerabilities affect Claroline e-Learning Application These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating ...