Claroline 1.8 - tracking/toolaccess_details.php toolId Parameter Cross-Site Scripting

admin 2023-12-11 16:17:11 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
Claroline 1.8 - tracking/toolaccess_details.php toolId Parameter Cross-Site Scripting

CVE编号

CVE-2008-3315

利用情况

暂无

补丁情况

N/A

披露时间

2008-07-26
漏洞描述
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) query string to (a) announcements/messages.php; (b) lostPassword.php and (c) profile.php in auth/; (d) calendar/myagenda.php; (e) group/group.php; (f) learningPath.php, (g) learningPathList.php, and (h) module.php in learnPath/; (i) phpbb/index.php; (j) courseLog.php, (k) course_access_details.php, (l) delete_course_stats.php, (m) userLog.php, and (n) user_access_details.php in tracking/; (o) user/user.php; and (p) user/userInfo.php; the (2) view parameter to (q) tracking/courseLog.php; and the (3) toolId parameter to (r) tracking/toolaccess_details.php. NOTE: this may overlap CVE-2006-3257 and CVE-2005-1374.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
http://secunia.com/advisories/31201
http://securityreason.com/securityalert/4041
http://sourceforge.net/project/shownotes.php?release_id=615030
http://wiki.claroline.net/index.php/Changelog_1.8.x#Modification_between_clar...
http://www.securityfocus.com/archive/1/494655/100/0/threaded
http://www.securityfocus.com/bid/30346
http://www.vupen.com/english/advisories/2008/2167/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/43962
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 claroline claroline 1.8.10 -
CVSS3评分 4.3
  • 攻击路径 网络
  • 攻击复杂度 N/A
  • 权限要求 无
  • 影响范围 N/A
  • 用户交互 需要
  • 可用性 无
  • 保密性 无
  • 完整性 部分地
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-ID 漏洞类型
CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本)
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!