Vulnerabilities > CVE-2007-3517 - Cross-Site Scripting vulnerability in Claroline 1.8.3

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
claroline
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.

Vulnerable Configurations

Part Description Count
Application
Claroline
1

Exploit-Db

descriptionClaroline 1.8.3 $_SERVER['PHP_SELF'] Parameter Multiple Cross-Site Scripting Vulnerabilities. CVE-2007-3517. Webapps exploit for php platform
idEDB-ID:30259
last seen2016-02-03
modified2007-07-02
published2007-07-02
reportermunozferna
sourcehttps://www.exploit-db.com/download/30259/
titleClaroline <= 1.8.3 - $_SERVER'PHP_SELF' Parameter Multiple Cross-Site Scripting Vulnerabilities