5.1
CVSSv2

CVE-2007-4718

Published: 05/09/2007 Updated: 08/03/2011
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in inc/lib/language.lib.php in Claroline prior to 1.8.6 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline

Exploits

source: wwwsecurityfocuscom/bid/25521/info Claroline is prone to a local file-include vulnerability and multiple cross-site scripting vulnerabilities An attacker could exploit these issues to execute local script code in the context of the application and access sensitive data, which may aid in further attacksThe attacker may also be a ...