Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary PHP code via unknown vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/20300
http://www.claroline.net/news.php#85