Vulnerabilities > Dokeos > Dokeos > 1.8.4

DATE CVE VULNERABILITY TITLE RISK
2008-02-21 CVE-2008-0850 SQL Injection vulnerability in Dokeos 1.8.4
Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.
network
low complexity
dokeos CWE-89
7.5
2007-12-20 CVE-2007-6479 Permissions, Privileges, and Access Controls vulnerability in Dokeos 1.8.4
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.
network
dokeos CWE-264
4.9