Dokeos Multiple SQL Injection, HTML Injection, Cross-Site Scripting, and File Upload Vulnerabilities
BID:27792
Info
Dokeos Multiple SQL Injection, HTML Injection, Cross-Site Scripting, and File Upload Vulnerabilities
| Bugtraq ID: | 27792 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0850 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Alexandr Polyakov and Stas Svistunovich of Digital Security Research Group are credited with the discovery of these issues. |
| Vulnerable: |
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 Dokeos Open Source Learning & Knowledge Management Tool 1.8 Dokeos Open Source Learning & Knowledge Management Tool 1.6.5 Dokeos Open Source Learning & Knowledge Management Tool 1.6.4 Dokeos Open Source Learning & Knowledge Management Tool 1.6 RC2 Dokeos Open Source Learning & Knowledge Management Tool 1.5.5 Dokeos Open Source Learning & Knowledge Management Tool 1.5.4 Dokeos Open Source Learning & Knowledge Management Tool 1.5.3 Dokeos Open Source Learning & Knowledge Management Tool 1.5 Dokeos Open Source Learning & Knowledge Management Tool 1.4 Dokeos Open Source Learning & Knowledge Management Tool 1.6.4 (P1) Dokeos Open Source Learning & Knowledge Management 1.8.4 Dokeos Open Source Learning & Knowledge Management 1.8 |
| Not Vulnerable: |
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP2 |
Discussion
Dokeos Multiple SQL Injection, HTML Injection, Cross-Site Scripting, and File Upload Vulnerabilities
Dokeos is prone to multiple input-validation vulnerabilities including five SQL-injection issues, one HTML-injection issue, three cross-site scripting issues, and one arbitrary-file-upload issue.
Attackers can exploit these issues to execute arbitrary script code in the context of the webserver, compromise the application, steal cookie-based authentication credentials from legitimate users of the site, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Dokeos 1.8.4 SP2 are affected.
Dokeos is prone to multiple input-validation vulnerabilities including five SQL-injection issues, one HTML-injection issue, three cross-site scripting issues, and one arbitrary-file-upload issue.
Attackers can exploit these issues to execute arbitrary script code in the context of the webserver, compromise the application, steal cookie-based authentication credentials from legitimate users of the site, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Dokeos 1.8.4 SP2 are affected.
Exploit / POC
Solution / Fix
Dokeos Multiple SQL Injection, HTML Injection, Cross-Site Scripting, and File Upload Vulnerabilities
Solution:
The vendor released Dokeos 1.8.4 SP2 to address these issues. Please see the references for more information.
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4
Solution:
The vendor released Dokeos 1.8.4 SP2 to address these issues. Please see the references for more information.
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4
-
Dokeos dokeos-1.8.4-SP2.zip
http://www.dokeos.com/download/dokeos-1.8.4-SP2.zip
References
Dokeos Multiple SQL Injection, HTML Injection, Cross-Site Scripting, and File Upload Vulnerabilities
References:
References:
- FS#2218 - Security report from DSRG (Dokeos)
- Dokeos 1.8.4 security patch 2 (Dokeos)
- Dokeos Homepage (Dokeos)
- [DSECRG-08-015] Multiple Security Vulnerabilities in Dokeos 1.8.4 (Digital Security Research Group
)