Korean
<< Back
VID 21389
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Moodle program, according to its version number, has a SQL Injection Vulnerability in the 'glossary' module.
Moodle is an open-source PHP-based course management system (CMS) for Microsoft Windows, Unix, and Linux-based platforms. Moodle version 1.4.1 and possibly earlier versions allow an attacker to perform a SQL Injection attack in the glossary module, caused by improper validation of user-supplied input. By sending a specially-crafted URL request containing SQL code, an attacker could add, modify, or delete data in the backend database.

* Note: This check solely relied on the version number of Moodle on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=11427

* Platforms Affected:
Martin Dougiamas, Moodle 1.4.2 and earlier
Microsoft Windows Any version
Linux Any version
Unix Any version
Recommendation Upgrade to the latest version of Moodle (1.4.2 or later), available from the Moodle Download Web page at http://moodle.org/download/
Related URL CVE-2004-2232 (CVE)
Related URL 11608 (SecurityFocus)
Related URL 17965 (ISS)