|
RETIRED: Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
Dokeos is prone to multiple unspecified cross-site scripting vulnerabilities and multiple unspecified remote code-execution vulnerabilities because the application fails to sufficiently sanitize user-supplied data. Attackers can exploit these issues to execute arbitrary code in the context of the webserver, compromise the affected application, and steal cookie-based authentication credentials from legitimate users of the site. Other attacks are also possible. These issues affect Dokeos 1.8.4 prior to SP3. NOTE: This BID is now retired. It has been incorporated into BID 28599 (kses Multiple Input Validation Vulnerabilities), because the underlying problems are caused by the kses HTML filter. |
|
|
Privacy Statement |