Vulnerabilities > CVE-2007-3555 - Unspecified vulnerability in Moodle 1.7.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Moodle 1.7.1 Index.PHP Cross Site Scripting Vulnerability. CVE-2007-3555. Webapps exploit for php platform |
id | EDB-ID:30261 |
last seen | 2016-02-03 |
modified | 2007-07-02 |
published | 2007-07-02 |
reporter | MustLive |
source | https://www.exploit-db.com/download/30261/ |
title | Moodle 1.7.1 Index.PHP Cross-Site Scripting Vulnerability |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1691.NASL |
description | Several remote vulnerabilities have been discovered in Moodle, an online course management system. The following issues are addressed in this update, ranging from cross site scripting to remote code execution. Various cross site scripting issues in the Moodle codebase (CVE-2008-3326, CVE-2008-3325, CVE-2007-3555, CVE-2008-5432, MSA-08-0021, MDL-8849, MDL-12793, MDL-11414, MDL-14806, MDL-10276). Various cross site request forgery issues in the Moodle codebase (CVE-2008-3325, MSA-08-0023). Privilege escalation bugs in the Moodle codebase (MSA-08-0001, MDL-7755). SQL injection issue in the hotpot module (MSA-08-0010). An embedded copy of Smarty had several vulnerabilities (CVE-2008-4811, CVE-2008-4810 ). An embedded copy of Snoopy was vulnerable to cross site scripting (CVE-2008-4796 ). An embedded copy of Kses was vulnerable to cross site scripting (CVE-2008-1502 ). |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 35254 |
published | 2008-12-22 |
reporter | This script is Copyright (C) 2008-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/35254 |
title | Debian DSA-1691-1 : moodle - several vulnerabilities |
code |
|
References
- http://secunia.com/advisories/25929
- http://secunia.com/advisories/25929
- http://securityreason.com/securityalert/2857
- http://securityreason.com/securityalert/2857
- http://securityvulns.ru/Rdocument391.html
- http://securityvulns.ru/Rdocument391.html
- http://tracker.moodle.org/browse/MDL-10341
- http://tracker.moodle.org/browse/MDL-10341
- http://tracker.moodle.org/secure/IssueNavigator.jspa?mode=hide&requestId=10252
- http://tracker.moodle.org/secure/IssueNavigator.jspa?mode=hide&requestId=10252
- http://websecurity.com.ua/1045/
- http://websecurity.com.ua/1045/
- http://www.debian.org/security/2008/dsa-1691
- http://www.debian.org/security/2008/dsa-1691
- http://www.osvdb.org/36366
- http://www.osvdb.org/36366
- http://www.securityfocus.com/archive/1/472727/100/0/threaded
- http://www.securityfocus.com/archive/1/472727/100/0/threaded
- http://www.securityfocus.com/bid/24748
- http://www.securityfocus.com/bid/24748
- http://www.securitytracker.com/id?1018333
- http://www.securitytracker.com/id?1018333
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35239
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35239