Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4943

Опубликовано: 23 сент. 2006
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.8.2-1
edgy

not-affected

1.6.2-1ubuntu1.1
feisty

not-affected

1.6.3-2ubuntu1
gutsy

not-affected

1.8.2-1
hardy

not-affected

1.8.2-1
intrepid

not-affected

1.8.2-1
jaunty

not-affected

1.8.2-1
karmic

not-affected

1.8.2-1
upstream

released

1.6.2

Показывать по

Ссылки на источники

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 19 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

debian
почти 19 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session ...

github
больше 3 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

5 Medium

CVSS2