漏洞信息详情
Moodle 安全漏洞
漏洞简介
Moodle是一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。
Moodle 1.4.1及其早期版本的Glossary模块的sql.php存在安全漏洞。远程攻击者可以利用该漏洞修改SQL语句。
漏洞公告
Although it has been reported that this issue is fixed in version 1.4.2 of the affected software, this is not confirmed. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] .
参考网址
来源:SECUNIA
链接:http://secunia.com/advisories/13091
来源:BID
链接:https://www.securityfocus.com/bid/11608
来源:SECTRACK
链接:http://securitytracker.com/id?1012113
来源:OSVDB
链接:http://www.osvdb.org/11427
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/17965
来源:CONFIRM
链接:http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/mod/glossary/sql.php?r1=1.15.2.2&r2=1.15.2.3
受影响实体
- Moodle Moodle:1.1.1<!--2000-1-1-->
- Moodle Moodle:1.2<!--2000-1-1-->
- Moodle Moodle:1.2.1<!--2000-1-1-->
- Moodle Moodle:1.3<!--2000-1-1-->
- Moodle Moodle:1.3.1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...