Vulnerability Name: | CVE-2009-0501 (CCN-48499) | ||||||||||||
Assigned: | 2008-02-04 | ||||||||||||
Published: | 2008-02-04 | ||||||||||||
Updated: | 2020-12-01 | ||||||||||||
Summary: | Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive information and conduct "brute force attacks on user accounts" via unknown vectors. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-0501 Source: SUSE Type: UNKNOWN SUSE-SR:2009:007 Source: CCN Type: MSA-09-0006 Calendar export may allow brute force attacks Source: CONFIRM Type: Vendor Advisory http://moodle.org/security/ Source: CCN Type: SA33775 Moodle Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 34418 Source: CCN Type: Moodle Tracker Web site MDL-17203 Source: MLIST Type: UNKNOWN [oss-security] 20090204 CVS request - Moodle Source: CCN Type: OSVDB ID: 54087 Moodle Calendar Export Feature Unspecified Issue Source: CCN Type: BID-33612 Moodle Calendar Export Unspecified Information Disclosure Vulnerability Source: CCN Type: USN-791-1 Moodle vulnerabilities Source: XF Type: UNKNOWN moodle-calendar-info-disclosure(48499) Source: SUSE Type: SUSE-SR:2009:007 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |