dokeos kayıtları
dokeos üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2008-3363Kavram kanıtı | Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include anddokeos · e-learning system · CWE-22 | Yüksek7,5 | — | %3,3 | 30 Tem 2008 |
31İzleyin | CVE-2008-0850Kavram kanıtı | Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to dokeos · dokeos · CWE-89 | Yüksek7,5 | — | %2,4 | 20 Şub 2008 |
31İzleyin | CVE-2013-6341Kavram kanıtı | SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parametdokeos · dokeos · CWE-89 | Yüksek7,5 | — | %2,3 | 5 Ara 2013 |
31İzleyin | CVE-2008-1223İstismar yok | Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors.dokeos · open source learning and knowledge management tool | Yüksek7,5 | — | %2,2 | 10 Mar 2008 |
31İzleyin | CVE-2007-2889Kavram kanıtı | SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands dokeos · open source learning and knowledge management tool | Yüksek7,5 | — | %2,2 | 29 May 2007 |
30İzleyin | CVE-2009-2004İstismar yok | Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execudokeos · dokeos · CWE-89 | Yüksek7,5 | — | %1,3 | 8 Haz 2009 |
30İzleyin | CVE-2007-2902Kavram kanıtı | SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary dokeos · dokeos | Yüksek7,5 | — | %1,1 | 30 May 2007 |
29İzleyin | CVE-2006-2284Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the claroline · claroline | Orta6,8 | — | %6,7 | 9 May 2006 |
27İzleyin | CVE-2006-2286İstismar yok | Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.dokeos · dokeos · CWE-94 | Orta6,8 | — | %1,5 | 9 May 2006 |
27İzleyin | CVE-2009-2008İstismar yok | Multiple SQL injection vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via tdokeos · dokeos · CWE-89 | Orta6,8 | — | %1,0 | 8 Haz 2009 |
27İzleyin | CVE-2009-2005İstismar yok | Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication dokeos · dokeos · CWE-352 | Orta6,8 | — | %0,7 | 8 Haz 2009 |
23İzleyin | CVE-2006-4844Kavram kanıtı | PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly otherclaroline · claroline · CWE-94 | Orta5,1 | — | %10,4 | 18 Eyl 2006 |
21İzleyin | CVE-2006-2285Kavram kanıtı | PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in tdokeos · open source learning and knowledge management tool | Orta5,1 | — | %4,1 | 9 May 2006 |
21İzleyin | CVE-2009-2007İstismar yok | Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrarydokeos · dokeos · CWE-22 | Orta5,0 | — | %1,9 | 8 Haz 2009 |
21İzleyin | CVE-2012-5776İstismar yok | Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.dokeos · dokeos · CWE-79 | Orta5,4 | — | %0,5 | 29 Oca 2020 |
20İzleyin | CVE-2005-2598İstismar yok | Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitradokeos · dokeos | Orta5,0 | — | %1,6 | 17 Ağu 2005 |
19İzleyin | CVE-2007-6479Kavram kanıtı | Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8dokeos · dokeos · CWE-264 | Orta4,9 | — | %1,6 | 20 Ara 2007 |
18İzleyin | CVE-2008-0851Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1dokeos · e-learning system · CWE-79 | Orta4,3 | — | %4,0 | 20 Şub 2008 |
18İzleyin | CVE-2007-2901Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTMdokeos · dokeos | Orta4,3 | — | %1,8 | 30 May 2007 |
18İzleyin | CVE-2007-6574Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTMdokeos · open source learning and knowledge management · CWE-79 | Orta4,3 | — | %1,8 | 28 Ara 2007 |
17İzleyin | CVE-2008-1222İstismar yok | Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspedokeos · open source learning and knowledge management tool · CWE-79 | Orta4,3 | — | %1,2 | 10 Mar 2008 |
17İzleyin | CVE-2006-3924İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos before 1.6.5 allow remote attackers to inject arbitrary web script or HTML viadokeos · dokeos · CWE-79 | Orta4,3 | — | %1,2 | 28 Tem 2006 |
17İzleyin | CVE-2009-2009İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web scdokeos · dokeos · CWE-79 | Orta4,3 | — | %1,1 | 8 Haz 2009 |
10İzleyin | CVE-2009-2006İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web scdokeos · dokeos · CWE-79 | Düşük2,6 | — | %1,3 | 8 Haz 2009 |
- CVE-2008-336331İzleyin
Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and
YüksekCVSS 7,5Kavram kanıtıEPSS %3dokeos · e-learning system30 Tem 2008
- CVE-2008-085031İzleyin
Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to
YüksekCVSS 7,5Kavram kanıtıEPSS %2dokeos · dokeos20 Şub 2008
- CVE-2013-634131İzleyin
SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language paramet
YüksekCVSS 7,5Kavram kanıtıEPSS %2dokeos · dokeos5 Ara 2013
- CVE-2008-122331İzleyin
Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors.
YüksekCVSS 7,5İstismar yokEPSS %2dokeos · open source learning and knowledge management tool10 Mar 2008
- CVE-2007-288931İzleyin
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %2dokeos · open source learning and knowledge management tool29 May 2007
- CVE-2009-200430İzleyin
Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execu
YüksekCVSS 7,5İstismar yokEPSS %1dokeos · dokeos8 Haz 2009
- CVE-2007-290230İzleyin
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %1dokeos · dokeos30 May 2007
- CVE-2006-228429İzleyin
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the
OrtaCVSS 6,8Kavram kanıtıEPSS %7claroline · claroline9 May 2006
- CVE-2006-228627İzleyin
Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.
OrtaCVSS 6,8İstismar yokEPSS %2dokeos · dokeos9 May 2006
- CVE-2009-200827İzleyin
Multiple SQL injection vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via t
OrtaCVSS 6,8İstismar yokEPSS %1dokeos · dokeos8 Haz 2009
- CVE-2009-200527İzleyin
Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication
OrtaCVSS 6,8İstismar yokEPSS %1dokeos · dokeos8 Haz 2009
- CVE-2006-484423İzleyin
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other
OrtaCVSS 5,1Kavram kanıtıEPSS %10claroline · claroline18 Eyl 2006
- CVE-2006-228521İzleyin
PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in t
OrtaCVSS 5,1Kavram kanıtıEPSS %4dokeos · open source learning and knowledge management tool9 May 2006
- CVE-2009-200721İzleyin
Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary
OrtaCVSS 5,0İstismar yokEPSS %2dokeos · dokeos8 Haz 2009
- CVE-2012-577621İzleyin
Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.
OrtaCVSS 5,4İstismar yokEPSS %1dokeos · dokeos29 Oca 2020
- CVE-2005-259820İzleyin
Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitra
OrtaCVSS 5,0İstismar yokEPSS %2dokeos · dokeos17 Ağu 2005
- CVE-2007-647919İzleyin
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8
OrtaCVSS 4,9Kavram kanıtıEPSS %2dokeos · dokeos20 Ara 2007
- CVE-2008-085118İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1
OrtaCVSS 4,3Kavram kanıtıEPSS %4dokeos · e-learning system20 Şub 2008
- CVE-2007-290118İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTM
OrtaCVSS 4,3Kavram kanıtıEPSS %2dokeos · dokeos30 May 2007
- CVE-2007-657418İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTM
OrtaCVSS 4,3Kavram kanıtıEPSS %2dokeos · open source learning and knowledge management28 Ara 2007
- CVE-2008-122217İzleyin
Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspe
OrtaCVSS 4,3İstismar yokEPSS %1dokeos · open source learning and knowledge management tool10 Mar 2008
- CVE-2006-392417İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos before 1.6.5 allow remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3İstismar yokEPSS %1dokeos · dokeos28 Tem 2006
- CVE-2009-200917İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web sc
OrtaCVSS 4,3İstismar yokEPSS %1dokeos · dokeos8 Haz 2009
- CVE-2009-200610İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web sc
DüşükCVSS 2,6İstismar yokEPSS %1dokeos · dokeos8 Haz 2009