CVE-2008-0850
Last modified
CVE-2008-0850 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.. EPSS estimates a 2.38% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dokeos | Dokeos | 1.8.4 |
References
- http://secunia.com/advisories/28974Vendor Advisory
- http://secunia.com/advisories/28974Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0850?
How severe is CVE-2008-0850?
How do I fix CVE-2008-0850?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-0844SQL injection vulnerability in index.php in the PccookBook (…
- CVE-2008-0845SQL injection vulnerability in wp-people-popup.php in Dean L…
- CVE-2008-0846SQL injection vulnerability in index.php in the com_profile …
- CVE-2008-0847SQL injection vulnerability in print.php in the myTopics mod…
- CVE-2008-0848Cross-site scripting (XSS) vulnerability in lostsheep.php in…
- CVE-2008-0849SQL injection vulnerability in index.php in the Downloads (c…
- CVE-2008-0851Multiple cross-site scripting (XSS) vulnerabilities in Dokeo…
- CVE-2008-0852freeSSHd 1.2 and earlier allows remote attackers to cause a …
- CVE-2008-0853SQL injection vulnerability in the com_detail component for …
- CVE-2008-0854SQL injection vulnerability in the com_salesrep component fo…
- CVE-2008-0855SQL injection vulnerability in the Facile Forms (com_facilef…
- CVE-2008-0856Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 …
Are you affected by CVE-2008-0850?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
