vendor:
E-Learning System
by:
Digital Security Research Group [DSecRG]
N/A
CVSS
N/A
Local File Include
CWE
Product Name: E-Learning System
Affected Version From: 1.8.2005
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
DSecRG Advisory #DSECRG-08-029
Dokeos E-Learning System system has local file include vulnerability in script user_portal.php. Registered user can use this vulnerability.
Mitigation:
Fixing this issue can be done by replacing line 770 of /user_portal.php by: if (!empty ($_GET['include']) && preg_match('/^[a-zA-Z0-9_-]*\.html$/',$_GET['include'])