Oval Definition:oval:org.mitre.oval:def:8102
Revision Date:2014-06-23Version:17
Title:DSA-1724 moodle -- several vulnerabilities
Description:Several vulnerabilities have been discovered in Moodle, an online course management system. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that the information stored in the log tables was not properly sanitised, which could allow attackers to inject arbitrary web code. It was discovered that certain input via the "Login as" function was not properly sanitised leading to the injection of arbitrary web script. Dmitry E. Oboukhov discovered that the SpellCheker plugin creates temporary files insecurely, allowing a denial of service attack. Since the plugin was unused, it is removed in this update.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-5153
CVE-2009-0500
CVE-2009-0502
DSA-1724
Platform(s):Debian GNU/Linux 4.0
Product(s):moodle
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Installed architecture is all
  • AND moodle is earlier than 1.6.3-2+etch2
  • BACK