Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-0123

Опубликовано: 12 янв. 2008
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodlefixed1.9.8-1package

Примечания

  • the issue itself has a quite small attack vector

  • and considering that the apache configuration that comes

  • with moodle limits connections to localhost this is no issue

EPSS

Процентиль: 75%
0.00956
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

nvd
больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

EPSS

Процентиль: 75%
0.00956
Низкий