CVE-2006-2285

Dokeos 1.6.4 - RCE

Title source: llm
STIX 2.1

Description

PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by beford · perlwebappsphp
https://www.exploit-db.com/exploits/1765

Scores

EPSS 0.0630
EPSS Percentile 91.0%

Details

Status published
Products (7)
dokeos/open_source_learning_and_knowledge_management_tool 1.4
dokeos/open_source_learning_and_knowledge_management_tool 1.5
dokeos/open_source_learning_and_knowledge_management_tool 1.5.3
dokeos/open_source_learning_and_knowledge_management_tool 1.5.4
dokeos/open_source_learning_and_knowledge_management_tool 1.5.5
dokeos/open_source_learning_and_knowledge_management_tool 1.6.4
dokeos/open_source_learning_and_knowledge_management_tool 1.6_rc2
Published May 10, 2006
Tracked Since Feb 18, 2026