7.5
CVSSv2

CVE-2007-2902

Published: 30/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the course parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dokeos dokeos

Exploits

#!/usr/bin/perl -w ################################################################################# # # # Dokeos <= 180 SQL Injection Exploit # # # # Discovered by: Silentz # # Payload: Admin ...