[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1724 moodle -- several vulnerabilities

ID: oval:org.mitre.oval:def:8102Date: (C)2009-12-15   (M)2021-06-02
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in Moodle, an online course management system. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that the information stored in the log tables was not properly sanitized, which could allow attackers to inject arbitrary web code. It was discovered that certain input via the "Login as" function was not properly sanitised leading to the injection of arbitrary web script. Dmitry E. Oboukhov discovered that the SpellCheker plugin creates temporary files insecurely, allowing a denial of service attack. Since the plugin was unused, it is removed in this update.

Platform:
Debian 4.0
Product:
moodle
Reference:
DSA-1724
CVE-2009-0500
CVE-2009-0502
CVE-2008-5153
CVE    3
CVE-2008-5153
CVE-2009-0502
CVE-2009-0500
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies