CVE-2007-4718
Claroline < 1.8.6 - Remote File Inclusion via Language Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4718. PoCs published by Fernando Munoz.
AI-analyzed exploit summary The provided content describes a local file inclusion (LFI) vulnerability in Claroline versions prior to 1.8.6, allowing attackers to access sensitive files via path traversal. It also mentions XSS vulnerabilities but lacks executable exploit code.
Description
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
Exploits (1)
The provided content describes a local file inclusion (LFI) vulnerability in Claroline versions prior to 1.8.6, allowing attackers to access sensitive files via path traversal. It also mentions XSS vulnerabilities but lacks executable exploit code.