📦

open_source_learning_and_knowledge_management_tool

Vendor: dokeos

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 2 Remote Access
Total CVEs 12 Total Indexed
Avg. EPSS 3.60% Exploit Prob.
Latest CVE CVE-2008-1222 Mar 10

Security Vulnerability Index

Page 1 / 2
4.3 CVSS

Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.22%
7.5 CVSS

Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: 2.23%
4.3 CVSS
CVE-2007-6574
Exploit Found

Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.

EPSS: 1.77%
7.5 CVSS
CVE-2007-2889
Exploit Found

SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.

EPSS: 2.16%
5.1 CVSS
CVE-2006-4844
RCE Exploit Found

PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.

EPSS: 10.08%
5.1 CVSS
CVE-2006-2285
Exploit Found

PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.

EPSS: 4.14%