CVE-2007-2901

Dokeos <1.8.0 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Silentz · perlwebappsphp
https://www.exploit-db.com/exploits/3974

Scores

EPSS 0.0699
EPSS Percentile 91.5%

Details

Status published
Products (1)
dokeos/dokeos < 1.8.0
Published May 30, 2007
Tracked Since Feb 18, 2026