CVE-2007-4718

Claroline < 1.8.5 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Fernando Munoz · htmlwebappsphp
https://www.exploit-db.com/exploits/30556

Scores

EPSS 0.0586
EPSS Percentile 90.6%

Details

CWE
CWE-22
Status published
Products (1)
claroline/claroline < 1.8.5
Published Sep 05, 2007
Tracked Since Feb 18, 2026