CVE-2007-4742 Information

Description

Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php which reveals the path in an error message in some circumstances as demonstrated by a parameter value containing an XSS sequence.

Reference

http://cvs.claroline.net/cgi-bin/viewcvs.cgi/claroline/claroline/admin/adminusers.php?only_with_tag=V_1_8&r2=1.109.2.1&r1=1.10 http://osvdb.org/39160 http://www.claroline.net/forum/viewtopic.php?t=13448

Share on: