HSC Research Group -
Written by Hackers Center
Saturday, 22 December 2007 12:45
[HSC] Dokeos Multiple Cross-Site Scripting Vulnerabilities
Dokeos is a learning management system used to manage e-learning. It"s prone to
cross-site scripting vulnerability. An attacker may leverage this issue to have
arbitrary script code execute in the browser of an unsuspecting user in the
context of the affected site. This may help the attacker steal cookie-based
authentication credentials and launch other attacks.
Hackers Center Security Group (http://www.hackerscenter.com)
Class: Input Validation Error
Vendor: Dokeos http://www.dokeos.com/
Product: Dokeos 1.8.4 & Previous
* Attackers can exploit these issues via a web client.
Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!