Moodle is prone to multiple security-bypass vulnerabilities.
Credit:
The information has been provided by Frederic Hoogstoel, Fabio Souto, Andrea Bicciolo, John Fitchett, Kathryn Fortin, Mark Nelson, Eloy Lafuente, Ivo Smelhaus, and Petr Skoda .
The original article can be found at: http://www.securityfocus.com/bid/52631
Vulnerable Systems:
* Moodle Moodle 2.2.1
* Moodle Moodle 2.1.4
* Moodle Moodle 2.1.2
* Moodle Moodle 2.1.1
* Moodle Moodle 2.0.7
* Moodle Moodle 2.0.5
* Moodle Moodle 2.0.4
* Moodle Moodle 2.0.3
* Moodle Moodle 2.0.2
* Moodle Moodle 2.0.1
* Moodle Moodle 2.0.1
* Moodle Moodle 1.9.16
* Moodle Moodle 1.9.14
* Moodle Moodle 1.9.13
* Moodle Moodle 1.9.12
* Moodle Moodle 1.9.11
* Moodle moodle 1.9.10
* Moodle Moodle 1.9.10
* Moodle Moodle 1.9.9
* Moodle moodle 1.9.8
* Moodle Moodle 1.9.7
* Moodle moodle 1.9.6
* Moodle Moodle 1.9.5
* Moodle Moodle 1.9.4
* Moodle moodle 1.9.3
* Moodle moodle 1.9.2
* Moodle Moodle 1.9.1
* Moodle Moodle 2.2
* Moodle Moodle 2.1.3
* Moodle Moodle 2.1
* Moodle Moodle 2.0.6
* Moodle Moodle 2.0
* Moodle Moodle 1.9.15
* Moodle Moodle 1.9
Immune Systems:
* Moodle Moodle 2.2.2
* Moodle Moodle 2.1.5
* Moodle Moodle 2.0.8
* Moodle Moodle 1.9.17
Successful attacks can allow an attacker to bypass certain security restrictions and obtain sensitive information.
Vendor Status:
Vendor had issued an update for this vulnerability
Patch Availability:
http://www.moodle.org/
CVE Information:
CVE-2012-1155
CVE-2012-1157
CVE-2012-1169
CVE-2012-1158
CVE-2012-1159
CVE-2012-1160
CVE-2012-1161
CVE-2012-1170
CVE-2012-1168
Disclosure Timeline:
Initial Release: Mar 20 2012
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by