PT-2008-4733 · Moodle · Moodle

Richard Brain

·

Publicado

2008-07-25

·

Atualizado

2018-10-11

·

CVE-2008-3327

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle version 1.6.5
Description The issue allows remote attackers to obtain sensitive information via a direct request to certain PHP files, specifically "blog/blogpage.php" and "course/report/stats/report.php", when display errors is enabled. This reveals the installation path in an error message.
Recommendations For Moodle version 1.6.5, consider disabling the display errors setting to prevent sensitive information disclosure. Additionally, restrict access to the "blog/blogpage.php" and "course/report/stats/report.php" files until a more permanent solution is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3327

Produtos afetados

Moodle