vendor:
Claroline Open Source e-Learning
by:
beford
7,5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: Claroline Open Source e-Learning
Affected Version From: 1.7.5
Affected Version To: 1.7.5
Patch Exists: NO
Related CWE: N/A
CPE: a:claroline:claroline_open_source_e-learning
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Claroline Open Source e-Learning 1.7.5 Remote File Include
The file claroline/auth/extauth/drivers/ldap.inc.php uses the variable clarolineRepositorySys in a include() function without being declared. There are other files vulnerable in the same folder, this exploit only attacks ldap.inc.php. There is other vulnerable file claroline/auth/extauth/casProcess.inc.php it uses the claro_CasLibPath in a include function but this is not being declared either, so pwnt, RFI.
Mitigation:
The vendor should declare the variables used in the include() function.