Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities

Dokeos is prone to multiple unspecified cross-site scripting vulnerabilities and multiple unspecified remote code-execution vulnerabilities because the application fails to sufficiently sanitize user-supplied data.

Attackers can exploit these issues to execute arbitrary code in the context of the webserver, compromise the affected application, and steal cookie-based authentication credentials from legitimate users of the site. Other attacks are also possible.

These issues affect Dokeos 1.8.4 prior to SP3.

NOTE: This BID is now retired. It has been incorporated into BID 28599 (kses Multiple Input Validation Vulnerabilities), because the underlying problems are caused by the kses HTML filter.







 

Privacy Statement
Copyright 2007, SecurityFocus