CVE-2007-6479 describes an unrestricted file upload vulnerability in Dokeos 1.8.4, specifically within the "My productions" component (main/auth/profile.php). Authenticated users can exploit this by uploading arbitrary PHP files with double extensions, which can then be executed from a predictable URI. The vulnerability has a CVSS score of 4.9, indicating medium severity, with an attack vector of network, medium attack complexity, and requiring authentication, leading to partial confidentiality and integrity impacts. Its FAUCET Risk Score is 78/100, suggesting a notable risk. While not listed in CISA's KEV catalog and showing no active exploitation or community discussion, exploit code is publicly available via ExploitDB (EDB-4753), indicating a known method for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.4CPE matchmatch criteria | cpe:2.3:a:dokeos:dokeos:1.8.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.