CVE-2006-4943

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:17

Type Values Removed Values Added
References () http://docs.moodle.org/en/Release_notes#Moodle_1.6.2 - () http://docs.moodle.org/en/Release_notes#Moodle_1.6.2 -

Information

Published : 2006-09-23 00:07

Updated : 2024-11-21 00:17


NVD link : CVE-2006-4943

Mitre link : CVE-2006-4943

CVE.ORG link : CVE-2006-4943


JSON object : View

Products Affected

moodle

  • moodle