PT-2009-2622 · Docebo · Docebo

Egix

·

Publicado

2009-09-02

·

Atualizado

2017-09-29

·

CVE-2008-7153

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Docebo versions 3.5.0.3 and earlier
Description A SQL injection issue exists in the autoDetectRegion function in doceboCore/lib/lib.regset.php, allowing remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. This can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.
Recommendations For Docebo versions 3.5.0.3 and earlier, update to a version that fixes this issue to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the autoDetectRegion function until a patch is available. Avoid using the Accept-Language HTTP header in a way that could be exploited by this issue until the vulnerability is resolved.

Exploit

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7153

Produtos afetados

Docebo