CVE-2008-0850 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php (2) tracking_list_coaches_column parameter to main/mySpace/index.php (3) tutor_name parameter to main/create_course/add_course.php the (4) Referer HTTP header to index.php and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.
Reference
http://projects.dokeos.com/index.php?do=details&task_id=2218 http://secunia.com/advisories/28974 http://securityreason.com/securityalert/3687 http://www.securityfocus.com/archive/1/488314/100/0/threaded http://www.securityfocus.com/bid/27792 http://www.securitytracker.com/id?1019425 http://www.vupen.com/english/advisories/2008/0587
Share on: