Claroline rqmkhtml.php directory traversal

claroline-rqmkhtml-directory-traversal (25561) The risk level is classified as MediumMedium Risk

Description:

Claroline could allow a remote attacker to traverse directories and view sensitive information. A remote attacker could send a specially-crafted URL request to the rqmkhtml.php script containing "dot dot" sequences (/../) in the 'file' parameter to traverse directories on the system and view arbitrary files on the system.


Consequences:

Obtain Information

Remedy:

Refer to the Claroline Web site for patch information. See References.

References:

  • Claroline Web site: Claroline.net - Open Source eLearning.
  • BID-17343: Claroline Rqmkhtml.PHP Information Disclosure Vulnerability
  • CVE-2006-1594: Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use .. (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.php or (2) execute arbitrary code via the includePath parameter to learnPath/include/scormExport.inc.php.
  • SA19461: Claroline Multiple Vulnerabilities
  • VUPEN/ADV-2006-1187: Claroline Remote File Inclusion and Directory Traversal Vulnerabilities

Platforms Affected:

  • Claroline Claroline 1.7.4

Reported:

Mar 31, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page