Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3260

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2008-3260
Last Modified 29 Jan 2009 01:52:49
Published 22 Jul 2008 01:41:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-3260

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via (1) the cwd parameter in a rqMkHtml action to document/rqmkhtml.php, or the query string to (2) announcements/announcements.php, (3) calendar/agenda.php, (4) course/index.php, (5) course_description/index.php, (6) document/document.php, (7) exercise/exercise.php, (8) group/group_space.php, (9) phpbb/newtopic.php, (10) phpbb/reply.php, (11) phpbb/viewtopic.php, (12) wiki/wiki.php, or (13) work/work.php in claroline/.

Vulnerable Systems

Application

  • Claroline 1.2

  • Claroline 1.3

  • Claroline 1.4

  • Claroline 1.5

  • Claroline 1.5.3

  • Claroline 1.5.4

  • Claroline 1.6

  • Claroline 1.6 Beta

  • Claroline 1.6 Rc1

  • Claroline 1.7

  • Claroline 1.7.1

  • Claroline 1.7.2

  • Claroline 1.7.3

  • Claroline 1.7.4

  • Claroline 1.7.5

  • Claroline 1.7.6

  • Claroline 1.7.7

  • Claroline 1.8.0

  • Claroline 1.8.1

  • Claroline 1.8.2

  • Claroline 1.8.3

  • Claroline 1.8.4

  • Claroline 1.8.5

  • Claroline 1.8.6

  • Claroline 1.8.7

  • Claroline 1.8.8

  • Claroline 1.8.9


References

XF - claroline-unknown-unspecified(43854)

BID - 30269

BUGTRAQ - 20080718 [DSECRG-08-030] Claroline 1.8.9 Multiple Security Vulnerabilities

CONFIRM - http://wiki.claroline.net/index.php/Changelog_1.8.x#Modification_between_claroline_1.8.9_and_1.8.10

CONFIRM - http://sourceforge.net/project/shownotes.php?release_id=613634

SREASON - 4020

SECUNIA - 31116


Last Updated: 27 May 2016 10:48:08