Exploitation Summary
EIP tracks 3 public exploits for CVE-2007-6574. PoCs published by Doz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 and earlier versions. It includes a proof-of-concept URL demonstrating the vulnerability but does not contain executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.
Exploits (3)
The provided text describes a cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 and earlier versions. It includes a proof-of-concept URL demonstrating the vulnerability but does not contain executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 and earlier versions. It explains the issue and provides an example URL demonstrating the vulnerability but does not include functional exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 and earlier versions. It includes a sample URL demonstrating how an attacker could inject arbitrary script code via the 'forum' parameter.