Vulnerability Name: | CVE-2008-5432 (CCN-47193) |
Assigned: | 2008-10-20 |
Published: | 2008-10-20 |
Updated: | 2020-12-01 |
Summary: | Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-79
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2008-5432
Source: SUSE Type: UNKNOWN SUSE-SR:2009:003
Source: CCN Type: MSA-08-0022 XSS through Wiki page titles
Source: CONFIRM Type: UNKNOWN http://moodle.org/mod/forum/discuss.php?d=108590
Source: CCN Type: SA33079 Moodle Unspecified Cross-Site Scripting Vulnerability
Source: SECUNIA Type: UNKNOWN 33079
Source: SECUNIA Type: UNKNOWN 33822
Source: DEBIAN Type: UNKNOWN DSA-1691
Source: DEBIAN Type: DSA-1691 moodle -- several vulnerabilities
Source: MLIST Type: UNKNOWN [oss-security] 20081209 CVE request: moodle (XSS)
Source: CCN Type: OSVDB ID: 50627 Moodle Wiki Page Names Unspecified XSS
Source: BID Type: UNKNOWN 32714
Source: CCN Type: BID-32714 Moodle Wiki Page Name Cross Site Scripting Vulnerability
Source: CCN Type: USN-791-1 Moodle vulnerabilities
Source: VUPEN Type: UNKNOWN ADV-2008-3405
Source: XF Type: UNKNOWN moodle-pagetitles-xss(47193)
Source: XF Type: UNKNOWN moodle-pagetitles-xss(47193)
Source: SUSE Type: SUSE-SR:2009:003 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration 1: cpe:/a:moodle:moodle:1.6.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5:-:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.2.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.4.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.2.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.1.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.5.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.3.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:*:*:*:*:*:*:*:* (Version <= 1.6.7)OR cpe:/a:moodle:moodle:1.7.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.0:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:moodle:moodle:1.6.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.7.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.6.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*AND cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*OR cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |