Secunia Logo
 
Moodle Multiple Vulnerabilities and Security Issues
Secunia Advisory: SA13515
Release Date: 2004-12-17
Last Update: 2005-01-03
Popularity: 11,182 views

Critical:
Moderately critical
Impact: Unknown
Security Bypass
Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch

Software:Moodle 1.2.x
Moodle 1.3.x
Moodle 1.4.x

Subscribe: Instant alerts on relevant vulnerabilities


Description:
Multiple vulnerabilities and security issues have been reported in Moodle. Some of these can potentially be exploited by malicious people to disclose sensitive information, and bypass certain security restrictions, and others have unknown impacts.

1) Some unspecified input validation errors results in cookie data and parameters for RSS feeds, ip atlas, glossary, forum, theme selection, SCORM module and document viewer not being properly validated.

2) An unspecified error may disclose uploaded files.

3) An unspecified error can be exploited to conduct directory traversal attacks.

4) An unspecified problem may disclose hidden activity glossaries.

5) An error may result in calendar events being disclosed to guest users.

6) An input validation error in "file.php" can be exploited to disclose session files via directory traversal attacks.

Example:
http://[victim]/moodle/file.php?file=/1/../sessions/

Some other unspecified issues have also been reported.

The vulnerabilities and security issues have been reported in version 1.4.2. Prior versions may also be affected.

Solution:
Update to version 1.4.3.
http://moodle.org/download/

Provided and/or discovered by:
1-5) Reported by vendor.
6) Bartek Nowotarski

Changelog:
2005-01-03: Added further information provided by Bartek Nowotarski. Updated "Description" section.


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 114 views
2. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 78 views
3. Microsoft Office Communications Server SIP INVITE Denial of Service // 66 views
4. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 50 views
5. Mozilla Firefox 3 Multiple Vulnerabilities // 42 views
6. Lito Lite CMS "cid" SQL Injection Vulnerability // 38 views
7. Active eWebquiz "useremail" and "password" SQL Injection Vulnerabilities // 35 views
8. Basic PHP CMS "id" SQL Injection Vulnerability // 35 views
9. Active Photo Gallery "username" and "password" SQL Injection // 33 views
10. RakhiSoftware Shopping Cart Multiple Vulnerabilities // 33 views