CVE-2006-4943

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

Information

Published : 2006-09-22 17:07

Updated : 2020-12-01 06:43


NVD link : CVE-2006-4943

Mitre link : CVE-2006-4943


JSON object : View

Advertisement

dedicated server usa

Products Affected

moodle

  • moodle