vendor:
Dokeos
by:
Silentz
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Dokeos
Affected Version From: 1.6.2005
Affected Version To: 1.6.2005
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Dokeos <= 1.6.5 SQL Injection Exploit
This exploit allows an attacker to retrieve the admin username and hash from the Dokeos <= 1.6.5 system. The vulnerability exists in the courseLog.php file, where an SQL query is executed without proper input validation.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a newer version of Dokeos that has patched this vulnerability.