Dokeos is a learning management
system<http://www.hackerscenter.com/archive/view.asp?id=28135#>used to
manage e-learning. It's prone to
cross-site scripting vulnerability. An attacker may leverage this issue to
have
arbitrary script code execute in the browser of an unsuspecting user in
the
context of the affected site. This may help the attacker steal
cookie-based
authentication credentials and launch other attacks.
Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz
Risk: Medium
Class: Input Validation Error
Remote: YES
Local: N/A
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.