Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4943

Опубликовано: 23 сент. 2006
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.8.2-1
edgy

not-affected

1.6.2-1ubuntu1.1
feisty

not-affected

1.6.3-2ubuntu1
gutsy

not-affected

1.8.2-1
hardy

not-affected

1.8.2-1
intrepid

not-affected

1.8.2-1
jaunty

not-affected

1.8.2-1
karmic

not-affected

1.8.2-1
upstream

released

1.6.2

Показывать по

Ссылки на источники

EPSS

Процентиль: 56%
0.00333
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 18 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

debian
больше 18 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session ...

github
около 3 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

EPSS

Процентиль: 56%
0.00333
Низкий

5 Medium

CVSS2