Vulnerabilities > CVE-2007-1647 - Information Disclosure vulnerability in Moodle
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
NONE Availability impact
NONE Summary
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.
Vulnerable Configurations
Exploit-Db
description | Moodle <= 1.5.2 (moodledata) Remote Session Disclosure Vulnerability. CVE-2007-1647. Webapps exploit for php platform |
file | exploits/php/webapps/3508.txt |
id | EDB-ID:3508 |
last seen | 2016-01-31 |
modified | 2007-03-18 |
platform | php |
port | |
published | 2007-03-18 |
reporter | xSh |
source | https://www.exploit-db.com/download/3508/ |
title | Moodle <= 1.5.2 moodledata Remote Session Disclosure Vulnerability |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | MOODLE_MOODLEDATA_INFO_DISCLOSURE.NASL |
description | The version of Moodle on the remote host allows a remote attacker to browse session files, which likely contain sensitive information about users of the application, such as password hashes and email addresses. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24874 |
published | 2007-03-23 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24874 |
title | Moodle 'moodledata/sessions' Session Files Remote Information Disclosure |
code |
|