vendor:
e-Learning Application
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-site scripting, SQL injection, directory traversal, and remote file include vulnerabilities
79, 89, 22, 98
CWE
Product Name: e-Learning Application
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Multiple remote input validation vulnerabilities in Claroline e-Learning Application
An attacker may exploit these issues to manipulate SQL queries to the underlying database, have arbitrary script code executed in the browser of an unsuspecting user, and execute arbitrary server-side scripts with the privileges of an affected Web server. This may facilitate the theft of sensitive information, potentially including authentication credentials, data corruption, and a compromise of the affected computer.
Mitigation:
Input validation should be performed to ensure that user-supplied input is properly sanitized prior to use in critical application functionality.