CVE-2008-0850

Dokeos 1.8.4 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2008-0850. PoCs published by Alexandr Polyakov.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Dokeos versions prior to 1.8.4 SP2. The provided URL manipulates the 'id' parameter in 'whoisonline.php' to extract database information such as user credentials and version details.

Description

Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Alexandr Polyakov · textwebappsphp
https://www.exploit-db.com/exploits/31194

This exploit demonstrates a SQL injection vulnerability in Dokeos versions prior to 1.8.4 SP2. The provided URL manipulates the 'id' parameter in 'whoisonline.php' to extract database information such as user credentials and version details.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Dokeos < 1.8.4 SP2
No auth needed
Prerequisites: Access to the target Dokeos installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Alexandr Polyakov · textwebappsphp
https://www.exploit-db.com/exploits/31195

The provided text describes multiple vulnerabilities in Dokeos, including SQL injection, XSS, and arbitrary file upload, but does not contain functional exploit code. It includes a sample HTTP request with a malformed Referer header, likely demonstrating an injection point.

Classification
Writeup 90%
Attack Type
Sqli | Xss | Other
Complexity
Trivial
Reliability
Theoretical
Target: Dokeos < 1.8.4 SP2
No auth needed
Prerequisites: Access to the target Dokeos application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Alexandr Polyakov · textwebappsphp
https://www.exploit-db.com/exploits/31199

The provided text describes multiple vulnerabilities in Dokeos, including SQL injection, XSS, and arbitrary file upload, but does not contain executable exploit code. It references a URL parameter for SQL injection but lacks a functional PoC.

Classification
Writeup 90%
Attack Type
Sqli | Xss | Other
Complexity
Trivial
Reliability
Theoretical
Target: Dokeos versions prior to 1.8.4 SP2
No auth needed
Prerequisites: Access to the target Dokeos installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Alexandr Polyakov · textwebappsphp
https://www.exploit-db.com/exploits/31200

This exploit demonstrates a SQL injection vulnerability in Dokeos by sending a malformed POST request to the course creation endpoint. The payload targets the 'tutor_name' parameter with a single quote to break the SQL query.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Dokeos < 1.8.4 SP2
Auth required
Prerequisites: Valid session cookie (dk_sid) · Access to the course creation endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27792
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3687
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488314/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019425
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28974
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0587

Scores

EPSS 0.0238
EPSS Percentile 81.7%

Details

CWE
CWE-89
Status published
Products (1)
dokeos/dokeos 1.8.4
Published Feb 21, 2008
Tracked Since Feb 18, 2026