CVE-2005-1376

critical

Description

Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/20287

http://www.securityfocus.com/bid/13407

http://www.claroline.net/news.php#85

http://securitytracker.com/id?1013822

http://secunia.com/advisories/15725

http://secunia.com/advisories/15161

http://marc.info/?l=bugtraq&m=111464607103407&w=2

Details

Source: Mitre, NVD

Published: 2005-05-03

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical