CVE-2006-1596
Claroline <= 1.7.4 - Remote File Inclusion via includePath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1596. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets Claroline <= 1.7.4 via a remote command execution vulnerability in 'scormExport.inc.php' due to unsafe file inclusion when 'register_globals' and 'allow_url_fopen' are enabled. It crafts an HTTP request to include a malicious remote PHP script, executing arbitrary commands.
Description
PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and earlier allows remote attackers to execute arbitrary PHP code via the includePath parameter.
Exploits (1)
This exploit targets Claroline <= 1.7.4 via a remote command execution vulnerability in 'scormExport.inc.php' due to unsafe file inclusion when 'register_globals' and 'allow_url_fopen' are enabled. It crafts an HTTP request to include a malicious remote PHP script, executing arbitrary commands.