Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-6099

Опубликовано: 27 янв. 2013
Источник: debian
EPSS Низкий

Описание

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodlefixed2.5-1package
moodlenot-affectedsqueezepackage
moodlefixed2.2.3.dfsg-2.6~wheezy2wheezypackage

EPSS

Процентиль: 42%
0.00199
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.

nvd
больше 12 лет назад

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.

github
больше 3 лет назад

Moodle Arbitrary File Read via Backup Functionality

EPSS

Процентиль: 42%
0.00199
Низкий