Bug tracker
Bug Details
Bug ID:188
Title:[30.5] Xss vulnerability
Author:fabio.pirovano
Date:19/02/2007 11:38
Last modified:19/02/2007 15:53
Product:Docebo 3.0.x
Product area:Admin Framework
Severity:Security warning
Status:Fixed and added to SVN
Description:Some XSS vulnerabilies, such as:

doceboLms/index.php?modname=xss_code&op=confirm

METODO: POST;
doceboCms/index.php
REQUEST DATA:
searchkey=xss_code&search=Cerca

Thanks to r00t_ati for the problem identification

A patch that fixes this bug has been released.

Unpack in root folder

Author Text