5.1
CVSSv2

CVE-2006-4844

Published: 19/09/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and previous versions, as used in Dokeos and possibly other products, allows remote malicious users to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline 1.5.3

claroline claroline 1.5.4

claroline claroline 1.7.3

claroline claroline 1.7.4

dokeos open source learning and knowledge management tool 1.6.4

dokeos open source learning and knowledge management tool 1.6.4_p1

claroline claroline 1.2

claroline claroline 1.3

claroline claroline 1.6_rc1

claroline claroline 1.6

claroline claroline 1.6_beta

claroline claroline 1.7.5

claroline claroline 1.7.6

dokeos open source learning and knowledge management tool 1.6.5

dokeos open source learning and knowledge management tool 1.6_rc2

claroline claroline 1.7

dokeos open source learning and knowledge management tool 1.4

dokeos open source learning and knowledge management tool 1.5

dokeos open source learning and knowledge management tool 1.5.3

claroline claroline

claroline claroline 1.4

claroline claroline 1.5

claroline claroline 1.7.1

claroline claroline 1.7.2

dokeos open source learning and knowledge management tool 1.5.4

dokeos open source learning and knowledge management tool 1.5.5

Exploits

Claroline Arbitrary File Inclusion Vendor: Claroline Product: Claroline Version: <= 177 Website: wwwclarolinenet/ BID: 20056 CVE: CVE-2006-4844 OSVDB: 28827 SECUNIA: 21931 Description: Claroline is a popular online Open Source e-Learning application used to allow teachers or education organizations to create and administrate co ...