CVE

Id
13804  
CVE No.
CVE-2005-2598  
Status
Candidate  
Description
Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitrary files or directories via the delete parameter to claroline/scorm/scormdocument.php, (2) move arbitrary files via the move_to and move_file parameters to claroline/document/document.php, or determine the existence of arbitrary files via the file parameter to (3) claroline/scorm/showinframes.php or (4) claroline/scorm/contents.php.  
Phase
Assigned (20050817)  
Votes
None (candidate not yet proposed)  
Comments