Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.
References 9 Total
- securityfocus.com: 17344 vdb-entry
- http://retrogod.altervista.org/claroline_174_incl_xpl.html
- secunia.com: 19461 third-party-advisory
- osvdb.org: 24284 vdb-entry
- archives.neohapsis.com: 20060331 Re: [Full-disclosure] Claroline <= 1.7.4 (scormExport.inc.php) Remote Code Execution Exploit by rgod mailing-list
- vupen.com: ADV-2006-1187 vdb-entry
- osvdb.org: 24285 vdb-entry
- exploit-db.com: 1627 exploit
- exchange.xforce.ibmcloud.com: claroline-rqmkhtml-xss(25562) vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 9 Total
- securityfocus.com: 17344 vdb-entryx_transferred
- http://retrogod.altervista.org/claroline_174_incl_xpl.html x_transferred
- secunia.com: 19461 third-party-advisoryx_transferred
- osvdb.org: 24284 vdb-entryx_transferred
- archives.neohapsis.com: 20060331 Re: [Full-disclosure] Claroline <= 1.7.4 (scormExport.inc.php) Remote Code Execution Exploit by rgod mailing-listx_transferred
- vupen.com: ADV-2006-1187 vdb-entryx_transferred
- osvdb.org: 24285 vdb-entryx_transferred
- exploit-db.com: 1627 exploitx_transferred
- exchange.xforce.ibmcloud.com: claroline-rqmkhtml-xss(25562) vdb-entryx_transferred