CVE Database
/

CVE-2009-4742

Back to search

CVE-2009-4742

Published: Mar 26, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module, reachable through index.php; (2) the word parameter in a play keyw action to the link module, reachable through index.php; (3) the id_certificate parameter in an elemmetacertificate action to the meta_certificate module, reachable through index.php; or (4) the id_certificate parameter in an elemcertificate action to the certificate module, reachable through index.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

36654
vdb-entry
x_refsource_BID
docebo-index-sql-injection(53701)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now