CVE-2007-2901
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors.
- Dokeos
- ≤ 1.8.0
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.8% (77th percentile)
- NVD status
- Modified
- Published
- 2007-05-30
CVE-2007-2901 at NVD
1 known exploit for CVE-2007-2901
Proof-of-concept code and exploit modules indexed by Sploitus