CVE Vulnerabilities

CVE-2006-6626

Published: Dec 18, 2006 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 1.5 (including) 1.5 (including)
Moodle Moodle 1.5.1 (including) 1.5.1 (including)
Moodle Moodle 1.5.2 (including) 1.5.2 (including)
Moodle Moodle 1.5.3 (including) 1.5.3 (including)
Moodle Moodle 1.6.1 (including) 1.6.1 (including)

References