Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Dokeos 'My production' Arbitrary File Upload Vulnerability

Dokeos is prone to a vulnerability that lets attackers upload arbitrary files because it fails to adequately sanitize user-supplied input.

NOTE: To exploit this issue, an attacker must have authenticated access to the affected application.

An attacker can exploit this issue to upload arbitrary files and execute malicious code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects Dokeos 1.8.4; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus