Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-3327

Опубликовано: 25 июл. 2008
Источник: debian
EPSS Низкий

Описание

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodleremovedpackage

Примечания

  • http://moodle.org/mod/forum/discuss.php?d=101403

  • Does not allow any attack vectors, apart from gaining non-sensible information

EPSS

Процентиль: 54%
0.00319
Низкий

Связанные уязвимости

nvd
почти 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

github
около 3 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

EPSS

Процентиль: 54%
0.00319
Низкий