Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown

CVE-2008-1222

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1223

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-0850

Disclosure Date: February 21, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.
0
Attacker Value
Unknown

CVE-2008-0851

Disclosure Date: February 21, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php.
0
Attacker Value
Unknown

CVE-2007-6574

Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.
0
Attacker Value
Unknown

CVE-2007-6479

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.
0
Attacker Value
Unknown

CVE-2007-2901

Disclosure Date: May 30, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-2902

Disclosure Date: May 30, 2007 (last updated October 04, 2023)
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter.
0
Attacker Value
Unknown

CVE-2007-2889

Disclosure Date: May 30, 2007 (last updated October 04, 2023)
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.
0
Attacker Value
Unknown

CVE-2006-4844

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.
0