CVE-2007-3517

Claroline 1.8.3 - Cross-Site Scripting via PATH_INFO

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3517. PoCs published by munozferna.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Claroline versions prior to 1.8.4. It explains the issue and provides a generic example URL but does not include functional exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.

Exploits (1)

exploitdb WRITEUP VERIFIED
by munozferna · textwebappsphp
https://www.exploit-db.com/exploits/30259

The provided text describes a cross-site scripting (XSS) vulnerability in Claroline versions prior to 1.8.4. It explains the issue and provides a generic example URL but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: Claroline < 1.8.4
No auth needed
Prerequisites: Access to a vulnerable Claroline instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://www.claroline.net/forum/viewtopic.php?t=11920
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36334
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2402
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36333
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25887
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24742

Scores

EPSS 0.0069
EPSS Percentile 71.9%

Details

Status published
Products (1)
claroline/claroline 1.8.3
Published Jul 03, 2007
Tracked Since Feb 18, 2026