Docebo SQL-Injection Vulnerability and Multiple Information Disclosure Vulnerabilities
BID:27211
Info
Docebo SQL-Injection Vulnerability and Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 27211 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7154 CVE-2008-7153 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | EgiX is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Docebo Docebo 3.5.0.3 |
| Not Vulnerable: | |
Discussion
Docebo SQL-Injection Vulnerability and Multiple Information Disclosure Vulnerabilities
Docebo is prone to multiple information-disclosure vulnerabilities and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or access sensitive data that may be used to launch further attacks.
These issues affect Docebo 3.5.0.3; other versions may also be vulnerable.
Docebo is prone to multiple information-disclosure vulnerabilities and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or access sensitive data that may be used to launch further attacks.
These issues affect Docebo 3.5.0.3; other versions may also be vulnerable.
Exploit / POC
Docebo SQL-Injection Vulnerability and Multiple Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example exploit is available:
Attackers can use a browser to exploit these issues.
The following example exploit is available:
Solution / Fix
Docebo SQL-Injection Vulnerability and Multiple Information Disclosure Vulnerabilities
Solution:
The vendor has committed fixes to the SVN repository. Please see the references for more information.
Solution:
The vendor has committed fixes to the SVN repository. Please see the references for more information.
References
Docebo SQL-Injection Vulnerability and Multiple Information Disclosure Vulnerabilities
References:
References: