Record summary

CVE-2005-1375 has a selected CVSS score of 7.5; EIP currently links 4 catalogued exploits.

Description

Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
4

Proofs of concept

4

Catalogued exploits

ExploitDBClaroline E-Learning 1.6 - Remote Hash SQL Injection (1)ExploitDB exploitby mh_p0rtalNot analyzed1 file
ExploitDB

PoC details
ExploitDBClaroline E-Learning 1.6 - Remote Hash SQL Injection (2)ExploitDB exploitby K-C0d3rNot analyzed1 file
ExploitDB

PoC details
ExploitDBClaroline E-Learning 1.5/1.6 - 'userInfo.php' Multiple SQL InjectionsExploitDB exploitby Sieg FriedNot analyzed1 file
ExploitDB

PoC details
ExploitDBClaroline E-Learning 1.5/1.6 - 'exercises_details.php?exo_id' SQL InjectionExploitDB exploitby Sieg FriedNot analyzed1 file
ExploitDB

PoC details

References

8