CVE-2006-4844
Claroline < 1.7.7 - Remote Code Execution via extAuthSource Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4844. PoCs published by GulfTech Security.
AI-analyzed exploit summary The writeup describes an arbitrary file inclusion vulnerability in Claroline <= 1.7.7 due to uninitialized array usage in claro_init_local.inc.php, allowing remote code execution when register_globals is enabled. No authentication is required for exploitation.
Description
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.
Exploits (1)
The writeup describes an arbitrary file inclusion vulnerability in Claroline <= 1.7.7 due to uninitialized array usage in claro_init_local.inc.php, allowing remote code execution when register_globals is enabled. No authentication is required for exploitation.