| Vulnerability Name: | CVE-2005-3649 (CCN-23060) | ||||||||
| Assigned: | 2005-11-11 | ||||||||
| Published: | 2005-11-11 | ||||||||
| Updated: | 2016-10-18 | ||||||||
| Summary: | jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.2 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Thu Nov 10 2005 - 14:25:51 CST Moodle <=1.6dev blind SQL Injection Source: MITRE Type: CNA CVE-2005-3649 Source: BUGTRAQ Type: UNKNOWN 20051110 Moodle <=1.6dev blind SQL Injection Source: CCN Type: Moodle Web site A Free, Open Source Course Management System for Online Learning Source: MISC Type: Exploit, Vendor Advisory http://rgod.altervista.org/moodle16dev.html Source: CCN Type: SA17526 Moodle Cross-Site Scripting and SQL Injection Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 17526 Source: SREASON Type: UNKNOWN 168 Source: OSVDB Type: UNKNOWN 20750 Source: CCN Type: OSVDB ID: 20749 Moodle plot.php user Parameter SQL Injection Source: CCN Type: OSVDB ID: 20750 Moodle jumpto.php jump Variable Arbitrary Site Redirect Source: VUPEN Type: UNKNOWN ADV-2005-2387 Source: XF Type: UNKNOWN moodle-jumpto-url-redirect(23060) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||