CVE-2007-4718
Claroline < 1.8.5 - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Fernando Munoz · htmlwebappsphp
https://www.exploit-db.com/exploits/30556
References (6)
Scores
EPSS
0.0586
EPSS Percentile
90.6%
Details
CWE
CWE-22
Status
published
Products (1)
claroline/claroline
< 1.8.5
Published
Sep 05, 2007
Tracked Since
Feb 18, 2026