CVE-2005-1375
HIGH 7.5EPSS 2.8%
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 2.76% chance of exploitation in the next 30 days, 85th percentile
- Published
- 2005-05-02
- Updated
- 2024-08-07
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/25553
- https://www.exploit-db.com/exploits/25552
- https://www.exploit-db.com/exploits/1053
- https://www.exploit-db.com/exploits/1052