Korean
<< Back
VID 21979
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Moodle software is vulnerable to multiple vulnerabilities which exist in versions prior to 1.6.2. Moodle is an open-source PHP-based course management system (CMS) for Microsoft Windows, Unix, and Linux-based platforms. Moodle versions prior to 1.6.2 are vulnerable to multiple vulnerabilities, which can be exploited by a remote attacker to conduct SQL injection and cross-site scripting attacks.

* References:
http://www.securityfocus.com/archive/1/446227/30/0/threaded
http://docs.moodle.org/en/Release_Notes#Moodle_1.6.2
http://www.frsirt.com/english/advisories/2006/3591
http://securitytracker.com/id?1016877
http://secunia.com/advisories/21899

* Platforms Affected:
Martin Dougiamas, Moodle versions prior to 1.6.2
Any operating system Any version
Recommendation Upgrade to the latest version of Moodle (1.6.2 or later), available from the Moodle Download Web site at http://download.moodle.org/
Related URL CVE-2006-4784,CVE-2006-4785,CVE-2006-4786 (CVE)
Related URL 19995,20085 (SecurityFocus)
Related URL 28903,28904,28905,29001 (ISS)