vendor:
Claroline
by:
James Bercegay
7,5
CVSS
HIGH
Arbitrary File Inclusion
94
CWE
Product Name: Claroline
Affected Version From: <= 1.7.7
Affected Version To: <= 1.7.7
Patch Exists: YES
Related CWE: CVE-2006-4844
CPE: a:claroline:claroline
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2006
Claroline Arbitrary File Inclusion
Claroline is vulnerable to an arbitray file inclusion issue that may allow for remote code execution. The vulnerability is due to an uninitialized array being used to include files. The vulnerable code in claro_init_local.inc.php can be seen below. Unfortunately there is no authentication needed to exploit this issue, thus allowing an attacker to easily include files via the extAuthSource[newUser] variable.
Mitigation:
An updated version of Claroline has been released and users are encouraged to upgrade as soon as possible.