CVE-2006-4844
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.4%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 10.42% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- claroline/claroline · dokeos/open source learning and knowledge management tool
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21931Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/21948Vendor Advisory
- http://www.claroline.net/wiki/index.php/Changelog_1.7.x#Modification_between_claroline_1.7.7_and_1.7.8Patch
- http://www.gulftech.org/?node=research&article_id=00112-09142006Exploit
- http://www.gulftech.org/?node=research&article_id=00112-09142006&
- http://www.securityfocus.com/bid/20056Patch
- http://www.vupen.com/english/advisories/2006/3638Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3639Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28943
- http://secunia.com/advisories/21931Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/21948Vendor Advisory
- http://www.claroline.net/wiki/index.php/Changelog_1.7.x#Modification_between_claroline_1.7.7_and_1.7.8Patch
- http://www.gulftech.org/?node=research&article_id=00112-09142006Exploit
- http://www.gulftech.org/?node=research&article_id=00112-09142006&
- http://www.securityfocus.com/bid/20056Patch
- http://www.vupen.com/english/advisories/2006/3638Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3639Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28943
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.