CVE-2006-4942

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:17

Type Values Removed Values Added
References () http://docs.moodle.org/en/Release_notes#Moodle_1.6.2 - () http://docs.moodle.org/en/Release_notes#Moodle_1.6.2 -

Information

Published : 2006-09-23 00:07

Updated : 2024-11-21 00:17


NVD link : CVE-2006-4942

Mitre link : CVE-2006-4942

CVE.ORG link : CVE-2006-4942


JSON object : View

Products Affected

moodle

  • moodle