Lucene search

K
cve[email protected]CVE-2006-1594
HistoryApr 03, 2006 - 10:04 a.m.

CVE-2006-1594

2006-04-0310:04:00
web.nvd.nist.gov
24
cve-2006-1594
directory traversal
claroline
remote code execution
nvd
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.03 Low

EPSS

Percentile

91.1%

Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use “…” (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.php or (2) execute arbitrary code via the includePath parameter to learnPath/include/scormExport.inc.php.

Affected configurations

NVD
Node
clarolineclarolineRange1.7.4
OR
clarolineclarolineMatch1.5
OR
clarolineclarolineMatch1.5.3
OR
clarolineclarolineMatch1.5.4
OR
clarolineclarolineMatch1.6
OR
clarolineclarolineMatch1.6_beta
OR
clarolineclarolineMatch1.6_rc1
OR
clarolineclarolineMatch1.7.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.03 Low

EPSS

Percentile

91.1%

Related for CVE-2006-1594