Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication of unspecified victims and add new personal agenda items via unknown vectors.Referenceshttp://www.vupen.com/english/advisories/2009/1300http://secunia.com/advisories/34879http://www.dokeos.com/wiki/index.php/Security#Dokeos_1.8http://holisticinfosec.org/content/view/112/45/http://www.securityfocus.com/bid/34928