Vulnerabilities > CVE-2004-0725 - Unspecified vulnerability in Moodle

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
moodle
nessus
exploit available

Summary

Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.

Exploit-Db

descriptionMoodle Help Script 1.x Cross Site Scripting Vulnerability. CVE-2004-0725. Webapps exploit for php platform
idEDB-ID:24279
last seen2016-02-02
modified2004-07-13
published2004-07-13
reportermorpheus[bd]
sourcehttps://www.exploit-db.com/download/24279/
titleMoodle Help Script 1.x - Cross-Site Scripting Vulnerability

Nessus

NASL familyCGI abuses : XSS
NASL idMOODLE_UNKNOWN_VULN.NASL
descriptionThe version of Moodle running on the remote host is affected by a cross-site scripting vulnerability. Input to the
last seen2020-06-01
modified2020-06-02
plugin id13843
published2004-07-26
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/13843
titleMoodle < 1.3.3 'help.php' 'file' Parameter XSS