CVE-2008-0851

Dokeos e-learning_system 1.8.4 - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2008-0851. PoCs published by Alexandr Polyakov.

AI-analyzed exploit summary The provided text describes multiple vulnerabilities in Dokeos, including XSS, SQL injection, and file upload issues, with a sample XSS payload. However, it lacks executable exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Alexandr Polyakov · textwebappsphp
https://www.exploit-db.com/exploits/31196

The provided text describes multiple vulnerabilities in Dokeos, including XSS, SQL injection, and file upload issues, with a sample XSS payload. However, it lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: Dokeos prior to 1.8.4 SP2
No auth needed
Prerequisites: Access to the target URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Alexandr Polyakov · textwebappsphp
https://www.exploit-db.com/exploits/31198

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Dokeos versions prior to 1.8.4 SP2. The PoC uses a crafted URL to inject JavaScript code via the 'message' parameter in the session_list.php script.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Dokeos < 1.8.4 SP2
No auth needed
Prerequisites: Access to the target Dokeos application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Alexandr Polyakov · textwebappsphp
https://www.exploit-db.com/exploits/31197

The provided text describes multiple vulnerabilities in Dokeos, including XSS, SQL injection, and file upload issues, with an example XSS payload. However, it lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: Dokeos prior to 1.8.4 SP2
No auth needed
Prerequisites: Access to the vulnerable endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27792
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3687
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488314/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019425
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28974
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0587

Scores

EPSS 0.0396
EPSS Percentile 89.1%

Details

CWE
CWE-79
Status published
Products (1)
dokeos/e-learning_system 1.8.4
Published Feb 21, 2008
Tracked Since Feb 18, 2026