Unrated severityNVD Advisory· Published May 10, 2006· Updated Apr 16, 2026
CVE-2006-2284
CVE-2006-2284
Description
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and the (2) claro_CasLibPath parameter in casProcess.inc.php.
Affected products
16cpe:2.3:a:claroline:claroline:1.5:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:claroline:claroline:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.6_beta:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.6_rc1:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:claroline:claroline:1.7.5:*:*:*:*:*:*:*
cpe:2.3:a:dokeos:dokeos:1.4:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:dokeos:dokeos:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:dokeos:dokeos:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:dokeos:dokeos:1.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:dokeos:dokeos:1.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:dokeos:dokeos:1.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:dokeos:dokeos:1.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:dokeos:dokeos:1.6_rc2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/20003nvdPatchVendor Advisory
- www.securityfocus.com/bid/17873nvdExploitPatch
- securityreason.com/securityalert/875nvd
- www.osvdb.org/25316nvd
- www.securityfocus.com/archive/1/433249/100/0/threadednvd
- www.vupen.com/english/advisories/2006/1701nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/26280nvd
- www.exploit-db.com/exploits/1766nvd
News mentions
0No linked articles in our index yet.