Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.
Link | Tags |
---|---|
http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/help.php | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16684 | vdb entry |
http://www.securityfocus.com/bid/10718 | patch vendor advisory vdb entry exploit |
http://marc.info/?l=bugtraq&m=108973588000027&w=2 | mailing list |