Unrated severityNVD Advisory· Published Sep 2, 2009· Updated Apr 23, 2026
CVE-2008-7153
CVE-2008-7153
Description
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.
Affected products
5cpe:2.3:a:docebo:docebo:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:docebo:docebo:*:*:*:*:*:*:*:*range: <=3.5.0.3
- cpe:2.3:a:docebo:docebo:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:docebo:docebo:3.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:docebo:docebo:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:docebo:docebo:3.5_beta:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.docebo.org/doceboCms/bugtracker/18_124/bugdetails/appid_24-bugid_198/bugtracker.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/27211nvdExploit
- secunia.com/advisories/28378nvdVendor Advisory
- osvdb.org/40138nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39589nvd
- www.exploit-db.com/exploits/4879nvd
- www.exploit-db.com/exploits/4891nvd
News mentions
0No linked articles in our index yet.