VYPR
Unrated severityNVD Advisory· Published Sep 2, 2009· Updated Apr 23, 2026

CVE-2008-7153

CVE-2008-7153

Description

SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.

Affected products

5
  • Docebo/Docebo5 versions
    cpe:2.3:a:docebo:docebo:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:docebo:docebo:*:*:*:*:*:*:*:*range: <=3.5.0.3
    • cpe:2.3:a:docebo:docebo:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:docebo:docebo:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:docebo:docebo:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:docebo:docebo:3.5_beta:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.