Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use ".." (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.php or (2) execute arbitrary code via the includePath parameter to learnPath/include/scormExport.inc.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Claroline Rqmkhtml.PHP信息泄露漏洞
Vulnerability Description
Claroline 1.7.4和以前版本中的document/rqmkhtml.php存在多个目录遍历漏洞,远程攻击者借助于访问document/rqmkhtml.php的rqEditHtml命令中file参数(参数值设置为'..')序列(1)可以读取任意文件,或者借助于到learnPath/include/srcormExport.inc.php的inlcudePath参数,执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A