Vulnerability Name: | CVE-2007-1647 (CCN-33147) | ||||||||
Assigned: | 2007-03-18 | ||||||||
Published: | 2007-03-18 | ||||||||
Updated: | 2017-10-11 | ||||||||
Summary: | Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N) 6.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:U/RC:UR)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1647 Source: CCN Type: Moodle Web site Moodle - A Free, Open Source Course Management System for Online Learning Source: OSVDB Type: UNKNOWN 43558 Source: CCN Type: OSVDB ID: 43558 Moodle moodledata/sessions/ Session Files Remote Information Disclosure Source: XF Type: UNKNOWN moodle-sessions-information-disclosure(33147) Source: XF Type: UNKNOWN moodle-sessions-information-disclosure(33147) Source: EXPLOIT-DB Type: UNKNOWN 3508 | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |