Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) search_term parameter to main/auth/courses.php; the (2) frm_title and (3) frm_content parameters in a new personal agenda item action; the (4) title and (5) tutor_name parameters in a new course action; and the (6) student and (7) course parameters to main/mySpace/myStudents.php. NOTE: vectors 2 and 3 might only be exploitable via a separate CSRF vulnerability.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dokeos | Dokeos | 1.8.5 |
Related Weaknesses (CWE)
References
- http://holisticinfosec.org/content/view/112/45/
- http://secunia.com/advisories/34879Vendor Advisory
- http://www.dokeos.com/wiki/index.php/Security#Dokeos_1.8PatchVendor Advisory
- http://www.securityfocus.com/bid/34928
- http://www.vupen.com/english/advisories/2009/1300PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50502
- http://holisticinfosec.org/content/view/112/45/
- http://secunia.com/advisories/34879Vendor Advisory
- http://www.dokeos.com/wiki/index.php/Security#Dokeos_1.8PatchVendor Advisory
- http://www.securityfocus.com/bid/34928
- http://www.vupen.com/english/advisories/2009/1300PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50500
FAQ
What is CVE-2009-2006?
CVE-2009-2006 is a vulnerability with a CVSS score of 2.6 (LOW). Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) search_term parameter to main/auth/...
How severe is CVE-2009-2006?
CVE-2009-2006 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2006?
Check the references section above for vendor advisories and patch information. Affected products include: Dokeos Dokeos.