7.5
CVSSv2

CVE-2009-4742

Published: 26/03/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote malicious users to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module, reachable through index.php; (2) the word parameter in a play keyw action to the link module, reachable through index.php; (3) the id_certificate parameter in an elemmetacertificate action to the meta_certificate module, reachable through index.php; or (4) the id_certificate parameter in an elemcertificate action to the certificate module, reachable through index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

docebo docebo 3.6.0.3

Exploits

************************************************************** Application: Docebo Version affected: 3603 Website: wwwdocebocom Discovered By: Andrea Fabrizi Email: andreafabrizi (at) gmail (dot) com [email concealed] Web: wwwandreafabriziit Vuln: Multiple SQL-Injection Vulnerabilities ***************************************** ...