Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-0502

Опубликовано: 10 фев. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.9.4.dfsg-0ubuntu1
gutsy

ignored

end of life, was needed
hardy

released

1.8.2-1ubuntu4.2
intrepid

released

1.8.2-1.2ubuntu2.1
jaunty

not-affected

1.9.4.dfsg-0ubuntu1
karmic

not-affected

1.9.4.dfsg-0ubuntu1
upstream

released

1.9.4

Показывать по

EPSS

Процентиль: 64%
0.00475
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.

nvd
больше 16 лет назад

Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.

debian
больше 16 лет назад

Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php ...

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.

EPSS

Процентиль: 64%
0.00475
Низкий

4.3 Medium

CVSS2