5
CVSSv2

CVE-2004-1425

Published: 31/12/2004 Updated: 01/12/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in file.php in Moodle 1.4.2 and previous versions allows remote malicious users to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 1.1.1

moodle moodle 1.3.4

moodle moodle 1.4.1

moodle moodle 1.3.0

moodle moodle 1.3.1

moodle moodle 1.2.0

moodle moodle 1.2.1

moodle moodle 1.4.2

moodle moodle 1.3.2

moodle moodle 1.3.3