CVE Vulnerabilities

CVE-2006-4941

Published: Sep 23, 2006 | Modified: Dec 01, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitrary web script or HTML via (1) the choose parameter in files/index.php and (2) the sub parameter in doc/index.php.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle * 1.6.1 (including)
Moodle Moodle 1.6.0 (including) 1.6.0 (including)

References