4.3
CVSSv2

CVE-2006-1595

Published: 03/04/2006 Updated: 19/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and previous versions allows remote malicious users to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline 1.5

claroline claroline 1.6_beta

claroline claroline 1.6_rc1

claroline claroline 1.7.2

claroline claroline

claroline claroline 1.5.3

claroline claroline 1.5.4

claroline claroline 1.6

Exploits

source: wwwsecurityfocuscom/bid/17343/info Claroline is prone to an information-disclosure vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application ...
source: wwwsecurityfocuscom/bid/17344/info Claroline is prone to a cross-site scripting vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affecte ...