PT-2006-3786 · Claroline · Claroline

Rgod

·

Published

2006-06-06

·

Updated

2017-10-19

·

CVE-2006-2868

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Claroline version 1.7.6
Description The issue allows remote attackers to execute arbitrary PHP code. This can be achieved by providing a URL in the includePath cookie to specific PHP files, such as auth/extauth/drivers/mambo.inc.php or auth/extauth/drivers/postnuke.inc.php.
Recommendations For Claroline version 1.7.6, consider restricting access to the auth/extauth/drivers/mambo.inc.php and auth/extauth/drivers/postnuke.inc.php files to minimize the risk of exploitation. Avoid using the includePath cookie with untrusted input until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2868

Affected Products

Claroline