PT-2009-2622 · Docebo · Docebo
Egix
·
Published
2009-09-02
·
Updated
2017-09-29
·
CVE-2008-7153
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Docebo versions 3.5.0.3 and earlier
Description
A SQL injection issue exists in the autoDetectRegion function in doceboCore/lib/lib.regset.php, allowing remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. This can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.
Recommendations
For Docebo versions 3.5.0.3 and earlier, update to a version that fixes this issue to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the autoDetectRegion function until a patch is available. Avoid using the Accept-Language HTTP header in a way that could be exploited by this issue until the vulnerability is resolved.
Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docebo