Filtered by vendor Claroline
Subscriptions
Total
31 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2006-0411 | 1 Claroline | 1 Claroline | 2025-04-03 | N/A |
claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges. | ||||
CVE-2006-1594 | 1 Claroline | 1 Claroline | 2025-04-03 | N/A |
Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use ".." (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.php or (2) execute arbitrary code via the includePath parameter to learnPath/include/scormExport.inc.php. | ||||
CVE-2006-1595 | 1 Claroline | 1 Claroline | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command. | ||||
CVE-2006-1596 | 1 Claroline | 1 Claroline | 2025-04-03 | N/A |
PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and earlier allows remote attackers to execute arbitrary PHP code via the includePath parameter. | ||||
CVE-2006-2284 | 2 Claroline, Dokeos | 2 Claroline, Dokeos | 2025-04-03 | N/A |
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and the (2) claro_CasLibPath parameter in casProcess.inc.php. | ||||
CVE-2005-1375 | 1 Claroline | 1 Claroline | 2025-04-03 | N/A |
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php. | ||||
CVE-2006-3257 | 1 Claroline | 1 Claroline | 2025-04-03 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.7.7 allow remote attackers to inject arbitrary HTML or web script via unspecified attack vectors, possibly including (1) calendar/myagenda.php, (2) document/document.php, (3) phpbb/newtopic.php, (4) tracking/userLog.php, and (5) wiki/page.php. | ||||
CVE-2022-37162 | 1 Claroline | 1 Claroline | 2024-11-21 | 5.4 Medium |
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event. | ||||
CVE-2022-37161 | 1 Claroline | 1 Claroline | 2024-11-21 | 6.1 Medium |
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload. | ||||
CVE-2022-37160 | 1 Claroline | 1 Claroline | 2024-11-21 | 5.4 Medium |
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user. | ||||
CVE-2022-37159 | 1 Claroline | 1 Claroline | 2024-11-21 | 9.8 Critical |
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. |