CVE-2006-4844

Properties

Published:
17.09.2006
Updated:
25.09.2006
Patch available:
Severity:
Medium
CVSS vector:
(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)
Product:
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Dokeos: Open Source Learning & Knowledge Management Tool
Claroline: Claroline
Claroline: Claroline
Claroline: Claroline
Claroline: Claroline
Claroline: Claroline
Claroline: Claroline
Claroline: Claroline
Claroline: Claroline

Vulnerability description

PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.

References:

http://www.gulftech.org/?node=research&article_id=00112-09142006: http://www.gulftech.org/?node=research&article_id=00112-09142006
http://www.claroline.net/wiki/index.php/Changelog_1.7.x#Modification_between_claroline_1.7.7_and_1.7.8: http://www.claroline.net/wiki/index.php/Changelog_1.7.x#Modification_between_claroline_1.7.7_and_1.7.8
BID: http://www.securityfocus.com/bid/20056
FRSIRT: http://www.frsirt.com/english/advisories/2006/3639
SECUNIA: http://secunia.com/advisories/21931
XF: http://xforce.iss.net/xforce/xfdb/28943
http://www.gulftech.org/?node=research&article_id=00112-09142006&: http://www.gulftech.org/?node=research&article_id=00112-09142006&
FRSIRT: http://www.frsirt.com/english/advisories/2006/3638
SECUNIA: http://secunia.com/advisories/21948