4.3
CVSSv2

CVE-2007-3555

Published: 04/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote malicious users to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 1.7.1

Vendor Advisories

Several remote vulnerabilities have been discovered in Moodle, an online course management system The following issues are addressed in this update, ranging from cross site scripting to remote code execution Various cross site scripting issues in the Moodle codebase (CVE-2008-3326, CVE-2008-3325, CVE-2007-3555, CVE-2008-5432, MSA-08-0021, MDL-884 ...

Exploits

source: wwwsecurityfocuscom/bid/24748/info Moodle is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website As a result, the attacker m ...