Full Disclosure mailing list archives

Multiple directory traversal vulnerabilities in Claroline ... NOT


From: "Robbe De Keyzer" <robbedekeyzer () hotmail com>
Date: Thu, 18 Aug 2005 17:16:30 +0200


Greetings,

In my previous post (http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/036041.html) I claimed that it was Claroline that was vulnerable. That is simply NOT true.

I was researching a different product that uses Claroline as a backend, and found the mentioned vulnerabilities in there. So, I made the wrong assumption that the Claroline product was vulnerable too. The vulnerable product's authors have been contacted, and a fix is underway. Until then, I'm not releasing its name.

So, once again, Claroline is NOT vulnerable. In fact, it's one of the safest E-Learning platforms out there.

Regards,

Robbe De Keyzer

_________________________________________________________________
Bescherm je Inbox: Phishing - hoe te herkennen, rapporteren en voorkomen http://www.msn.be/security/phishing/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: