CVE Vulnerabilities

CVE-2009-4304

Published: Dec 16, 2009 | Modified: Dec 01, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 1.8.1 (including) 1.8.1 (including)
Moodle Moodle 1.8.2 (including) 1.8.2 (including)
Moodle Moodle 1.8.3 (including) 1.8.3 (including)
Moodle Moodle 1.8.4 (including) 1.8.4 (including)
Moodle Moodle 1.8.5 (including) 1.8.5 (including)
Moodle Moodle 1.8.7 (including) 1.8.7 (including)
Moodle Moodle 1.8.8 (including) 1.8.8 (including)
Moodle Moodle 1.8.9 (including) 1.8.9 (including)
Moodle Moodle 1.8.10 (including) 1.8.10 (including)
Moodle Moodle 1.9.1 (including) 1.9.1 (including)
Moodle Moodle 1.9.2 (including) 1.9.2 (including)
Moodle Moodle 1.9.3 (including) 1.9.3 (including)
Moodle Moodle 1.9.4 (including) 1.9.4 (including)
Moodle Moodle 1.9.5 (including) 1.9.5 (including)
Moodle Moodle 1.9.6 (including) 1.9.6 (including)
Moodle Ubuntu dapper *
Moodle Ubuntu hardy *
Moodle Ubuntu intrepid *
Moodle Ubuntu jaunty *
Moodle Ubuntu karmic *
Moodle Ubuntu lucid *
Moodle Ubuntu maverick *

References