CVE-2005-2598 Information
Feb 14, 2021
cve
Description
Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier and possibly Claroline allow remote attackers to (1) delete arbitrary files or directories via the delete parameter to claroline/scorm/scormdocument.php (2) move arbitrary files via the move_to and move_file parameters to claroline/document/document.php or determine the existence of arbitrary files via the file parameter to (3) claroline/scorm/showinframes.php or (4) claroline/scorm/contents.php.
Reference
http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/036345.html http://seclists.org/lists/fulldisclosure/2005/Aug/0394.html http://secunia.com/advisories/16407
Share on: