Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-2230

Опубликовано: 28 июн. 2010
Источник: debian
EPSS Низкий

Описание

The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodlefixed1.9.9-1package
wordpressfixed3.0.4+dfsg-1package
wordpressnot-affectedlennypackage
egroupwarenot-affectedpackage

EPSS

Процентиль: 60%
0.00396
Низкий

Связанные уязвимости

ubuntu
почти 15 лет назад

The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.

nvd
почти 15 лет назад

The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.

github
около 3 лет назад

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

EPSS

Процентиль: 60%
0.00396
Низкий