PT-2005-4406 · Moodle · Moodle

Rgod

·

Publicado

2005-11-17

·

Atualizado

2016-10-18

·

CVE-2005-3649

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle version 1.5.2
Description The issue allows remote attackers to redirect users to other sites. This is achieved by manipulating the jump parameter in the jumpto.php file.
Recommendations For Moodle version 1.5.2, consider restricting access to the jumpto.php file until a patch is available. As a temporary workaround, avoid using the jump parameter in the jumpto.php file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3649

Produtos afetados

Moodle