Moodle Remote Glossary Module SQL Injection Vulnerability
BID:11608
Info
Moodle Remote Glossary Module SQL Injection Vulnerability
| Bugtraq ID: | 11608 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2004 12:00AM |
| Updated: | Nov 05 2004 12:00AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Moodle moodle 1.4.2 Moodle moodle 1.4.1 Moodle moodle 1.3.4 Moodle moodle 1.3.3 Moodle moodle 1.3.2 Moodle moodle 1.3.1 Moodle moodle 1.3 Moodle moodle 1.2.1 Moodle moodle 1.2 Moodle moodle 1.1.1 |
| Not Vulnerable: | |
Discussion
Moodle Remote Glossary Module SQL Injection Vulnerability
Moodle is affected by a remote SQL injection vulnerability in its glossary module. This issue is due to a failure of the application to properly sanitize user-supplier input.
An attacker may leverage this issue to execute arbitrary SQL queries against the underlying database, potentially facilitating disclosure or corruption of sensitive data. Other attacks are also possible.
Moodle is affected by a remote SQL injection vulnerability in its glossary module. This issue is due to a failure of the application to properly sanitize user-supplier input.
An attacker may leverage this issue to execute arbitrary SQL queries against the underlying database, potentially facilitating disclosure or corruption of sensitive data. Other attacks are also possible.
Exploit / POC
Moodle Remote Glossary Module SQL Injection Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Moodle Remote Glossary Module SQL Injection Vulnerability
Solution:
Although it has been reported that this issue is fixed in version 1.4.2 of the affected software, this is not confirmed. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Although it has been reported that this issue is fixed in version 1.4.2 of the affected software, this is not confirmed. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Moodle Remote Glossary Module SQL Injection Vulnerability
References:
References:
- Moodle Home Page (Moodle)
- Moodle Release Notes (Moodle)