VID |
21979 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Moodle software is vulnerable to multiple vulnerabilities which exist in versions prior to 1.6.2. Moodle is an open-source PHP-based course management system (CMS) for Microsoft Windows, Unix, and Linux-based platforms. Moodle versions prior to 1.6.2 are vulnerable to multiple vulnerabilities, which can be exploited by a remote attacker to conduct SQL injection and cross-site scripting attacks.
* References: http://www.securityfocus.com/archive/1/446227/30/0/threaded http://docs.moodle.org/en/Release_Notes#Moodle_1.6.2 http://www.frsirt.com/english/advisories/2006/3591 http://securitytracker.com/id?1016877 http://secunia.com/advisories/21899
* Platforms Affected: Martin Dougiamas, Moodle versions prior to 1.6.2 Any operating system Any version |
Recommendation |
Upgrade to the latest version of Moodle (1.6.2 or later), available from the Moodle Download Web site at http://download.moodle.org/ |
Related URL |
CVE-2006-4784,CVE-2006-4785,CVE-2006-4786 (CVE) |
Related URL |
19995,20085 (SecurityFocus) |
Related URL |
28903,28904,28905,29001 (ISS) |
|