7.5
CVE-2005-1375
- EPSS 2.76%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:12:56
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.76% | 0.843 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://marc.info/?l=bugtraq&m=111464607103407&w=2
http://secunia.com/advisories/15161
http://secunia.com/advisories/15725
http://securitytracker.com/id?1013822
http://www.claroline.net/news.php#85
http://www.securityfocus.com/bid/13407
https://exchange.xforce.ibmcloud.com/vulnerabilities/20298