Dokeos 'whoisonline.php' Remote Code Execution Vulnerability

Summary
Dokeos is prone to a remote code-execution vulnerability because the software fails to adequately sanitize user-supplied input. Exploiting this issue could allow an attacker to execute arbitrary code in the context of the vulnerable application. Dokeos prior to version 1.8.5 are vulnerable.
References