7.5
CVSSv2

CVE-2006-1594

Published: 03/04/2006 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and previous versions allow remote malicious users to use ".." (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.php or (2) execute arbitrary code via the includePath parameter to learnPath/include/scormExport.inc.php.

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline 1.5

claroline claroline 1.5.3

claroline claroline 1.6_beta

claroline claroline 1.6_rc1

claroline claroline 1.7.2

claroline claroline

claroline claroline 1.5.4

claroline claroline 1.6