Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2006-1596

Disclosure Date: April 03, 2006 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and earlier allows remote attackers to execute arbitrary PHP code via the includePath parameter.
0
Attacker Value
Unknown

CVE-2006-1595

Disclosure Date: April 03, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.
0
Attacker Value
Unknown

CVE-2006-0411

Disclosure Date: January 25, 2006 (last updated February 22, 2025)
claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.
0