online learning
Digital Security Research Group [DSecRG] Advisory #DSECRG-08-31
Application: Interact E-Learning System
Versions Affected: 2.4.1
Vendor URL: http://sourceforge.net/projects/cce-interact
Bug: Local File Include
Exploits: YES
Reported: 03.07.2008
Digital Security Research Group [DSecRG] Advisory #DSECRG-08-015
Application: Dokeos E-Learning System
Versions Affected: 1.8.4
Vendor URL: http://dokeos.com
Bugs: Multiple SQL Injections,Multiple Blind SQL Injections,Multiple XSS, etc.
Exploits: YES
Reported: 25.01.2008
Digital Security Research Group [DSecRG] Advisory #DSECRG-08-029
Application: Dokeos E-Learning System
Versions Affected: 1.8.5
Vendor URL: http://dokeos.com/
Bug: Local File Include
Exploits: YES
Reported: 01.07.2008
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
[HSC] Dokeos Multiple Cross-Site Scripting Vulnerabilities
Dokeos is a learning management system used to manage e-learning. It's prone to
cross-site scripting vulnerability. An attacker may leverage this issue to have
arbitrary script code execute in the browser of an unsuspecting user in the
context of the affected site. This may help the attacker steal cookie-based
authentication credentials and launch other attacks.
Found by Pepelux <pepelux[at]enye-sec.org>
eNYe-Sec - www.enye-sec.org
-- Description (by the author's page) --
eFront is an easy to use, visually attractive, SCORM compatible, eLearning
and Human Capital Development system. It is suitable for both company and
educational usage. The core eFront system is offered as open-source software
so you can download and start using it immediately. Check the functionality
matrix for different eFront editions.
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
3. *Vulnerability Description*
eFront [1] is an easy-to-use, open source and object-oriented
multilingual eLearning platform that can be used to build learning
communities, educate and retain the end-users.
eFront is vulnerable to local file inclusion vulnerability, which
allows an external remote attacker to upload an arbitrary file and
execute code on the vulnerable website learning platform.
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
I. BACKGROUND
---------------------
"eFront is a fully flexible eLearning system capable of fulfilling a wide
range of learning needs. With eFront you will discover new ways to perform
training tasks easier and faster, while keeping your people actively
engaged and in shape." from efrontlearning.net
I. BACKGROUND ---------------------
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com
II. DESCRIPTION ---------------------
VUPEN Vulnerability Research Team discovered four critical vulnerabilities
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com
II. DESCRIPTION
---------------------
* Infonomics
* Information Visualization
* Information Management
* Information Quality
* Technology-Enabled Information
* e-Learning
* e-Commerce
* e-Business
* e-Government
* e-Society
* System Design and Security for e-Services
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com
II. DESCRIPTION
---------------------
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com
II. DESCRIPTION
---------------------
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com
II. DESCRIPTION
---------------------
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
I. BACKGROUND
From the Moodle web site: "Moodle is a course management system (CMS) -
a free, Open Source software package designed using sound pedagogical
principles, to help educators create effective online learning
communities".
II. DESCRIPTION
A Remote Code Execution exists in Moodle 1.9.3.
Digital Security Research Group [DSecRG] Advisory #DSECRG-08-030
Application: Claroline eLearning and eWorking platform
Versions Affected: 1.8.9
Vendor URL: http://www.claroline.net/
Bug: Multiple XSS, Phishing Through URL Redirection, Change User Password XSRF Vulnerability
Exploits: YES
Reported: 04.07.2008
Digital Security Research Group [DSecRG] Advisory #DSECRG-08-032
Application: Claroline eLearning and eWorking platform
Versions Affected: 1.8.10
Vendor URL: http://www.claroline.net/
Bug: Multiple Linked XSS
Exploits: YES
Reported: 18.07.2008
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com
II. DESCRIPTION
---------------------
"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com
II. DESCRIPTION
---------------------
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
3) Vendor's Description of Software
"Over 450 million Internet-enabled desktops have installed Adobe
Shockwave Player. These people now have access to some of the best the
Web has to offer - including dazzling 3D games and entertainment,
interactive product demonstrations, and online learning applications."
Product Link:
http://www.adobe.com/products/shockwaveplayer/
======================================================================
|