RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
BID:28121
Info
RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 28121 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1223 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2008 12:00AM |
| Updated: | Jul 06 2016 01:34PM |
| Credit: | Allegro.pl is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP2 Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP1 |
| Not Vulnerable: |
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP3 |
Discussion
RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
Dokeos is prone to multiple unspecified cross-site scripting vulnerabilities and multiple unspecified remote code-execution vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attackers can exploit these issues to execute arbitrary code in the context of the webserver, compromise the affected application, and steal cookie-based authentication credentials from legitimate users of the site. Other attacks are also possible.
These issues affect Dokeos 1.8.4 prior to SP3.
NOTE: This BID is now retired. It has been incorporated into BID 28599 (kses Multiple Input Validation Vulnerabilities), because the underlying problems are caused by the kses HTML filter.
Dokeos is prone to multiple unspecified cross-site scripting vulnerabilities and multiple unspecified remote code-execution vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attackers can exploit these issues to execute arbitrary code in the context of the webserver, compromise the affected application, and steal cookie-based authentication credentials from legitimate users of the site. Other attacks are also possible.
These issues affect Dokeos 1.8.4 prior to SP3.
NOTE: This BID is now retired. It has been incorporated into BID 28599 (kses Multiple Input Validation Vulnerabilities), because the underlying problems are caused by the kses HTML filter.
Exploit / POC
RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues via a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues via a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
Solution:
The vendor released Dokeos 1.8.4 SP3 to address these issues. Please see the references for more information.
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP1
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP2
Solution:
The vendor released Dokeos 1.8.4 SP3 to address these issues. Please see the references for more information.
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP1
-
Dokeos dokeos-1.8.4-SP3.zip
http://www.dokeos.com/download/dokeos-1.8.4-SP3.zip
Dokeos Open Source Learning & Knowledge Management Tool 1.8.4 SP2
-
Dokeos dokeos-1.8.4-SP3.zip
http://www.dokeos.com/download/dokeos-1.8.4-SP3.zip
References
RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
References:
References:
- Dokeos Homepage (Dokeos)
- Dokeos Release Notes (Dokeos)