|
Moodle Multiple Vulnerabilities and Security Issues
|
|
Secunia Advisory:
|
SA13515
|
|
|
Release Date:
|
2004-12-17
|
|
Last Update:
|
2005-01-03
|
|
Popularity:
|
11,182 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Unknown Security Bypass Exposure of sensitive information
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Moodle 1.2.x Moodle 1.3.x Moodle 1.4.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: Multiple vulnerabilities and security issues have been reported in Moodle. Some of these can potentially be exploited by malicious people to disclose sensitive information, and bypass certain security restrictions, and others have unknown impacts.
1) Some unspecified input validation errors results in cookie data and parameters for RSS feeds, ip atlas, glossary, forum, theme selection, SCORM module and document viewer not being properly validated.
2) An unspecified error may disclose uploaded files.
3) An unspecified error can be exploited to conduct directory traversal attacks.
4) An unspecified problem may disclose hidden activity glossaries.
5) An error may result in calendar events being disclosed to guest users.
6) An input validation error in "file.php" can be exploited to disclose session files via directory traversal attacks.
Example:
http://[victim]/moodle/file.php?file=/1/../sessions/
Some other unspecified issues have also been reported.
The vulnerabilities and security issues have been reported in version 1.4.2. Prior versions may also be affected.
Solution: Update to version 1.4.3.
http://moodle.org/download/
Provided and/or discovered by: 1-5) Reported by vendor.
6) Bartek Nowotarski
Changelog: 2005-01-03: Added further information provided by Bartek Nowotarski. Updated "Description" section.
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|