4.3
CVSSv2

CVE-2008-3260

Published: 22/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 490
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Claroline prior to 1.8.10 allow remote malicious users to inject arbitrary web script or HTML via (1) the cwd parameter in a rqMkHtml action to document/rqmkhtml.php, or the query string to (2) announcements/announcements.php, (3) calendar/agenda.php, (4) course/index.php, (5) course_description/index.php, (6) document/document.php, (7) exercise/exercise.php, (8) group/group_space.php, (9) phpbb/newtopic.php, (10) phpbb/reply.php, (11) phpbb/viewtopic.php, (12) wiki/wiki.php, or (13) work/work.php in claroline/.

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline 1.5.4

claroline claroline 1.6

claroline claroline 1.7.5

claroline claroline 1.7.6

claroline claroline 1.8.5

claroline claroline 1.8.6

claroline claroline 1.2

claroline claroline 1.6_beta

claroline claroline 1.6_rc1

claroline claroline 1.7.7

claroline claroline 1.8.0

claroline claroline 1.8.7

claroline claroline 1.8.8

claroline claroline 1.3

claroline claroline 1.4

claroline claroline 1.7

claroline claroline 1.7.1

claroline claroline 1.8.1

claroline claroline 1.8.2

claroline claroline

claroline claroline 1.5

claroline claroline 1.5.3

claroline claroline 1.7.2

claroline claroline 1.7.3

claroline claroline 1.7.4

claroline claroline 1.8.3

claroline claroline 1.8.4

Exploits

source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the af ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the co ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affec ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting us ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the conte ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user ...
source: wwwsecurityfocuscom/bid/30269/info Claroline is prone to multiple input-validation vulnerabilities: 1 Multiple cross-site scripting vulnerabilities 2 A remote URI-redirection vulnerability An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of ...