Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2005/2387 | vdb entry |
http://marc.info/?l=bugtraq&m=113165668814241&w=2 | mailing list |
http://www.securityfocus.com/bid/15380/ | vdb entry exploit |
http://rgod.altervista.org/moodle16dev.html | exploit vendor advisory |
http://osvdb.org/20748 | vdb entry |
http://secunia.com/advisories/17526/ | third party advisory patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23058 | vdb entry |
http://securitytracker.com/id?1015181 | vdb entry |