2.6
CVSSv2

CVE-2008-3326

Published: 25/07/2008 Updated: 01/12/2020
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x prior to 1.6.7 and 1.7.x prior to 1.7.5 allows remote malicious users to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 1.6.0

moodle moodle 1.6.1

moodle moodle 1.6.2

moodle moodle 1.7.2

moodle moodle 1.7.3

moodle moodle 1.6.3

moodle moodle 1.6.4

moodle moodle 1.7.4

moodle moodle 1.6.5

moodle moodle 1.6.6

moodle moodle 1.7.1

Vendor Advisories

Several remote vulnerabilities have been discovered in Moodle, an online course management system The following issues are addressed in this update, ranging from cross site scripting to remote code execution Various cross site scripting issues in the Moodle codebase (CVE-2008-3326, CVE-2008-3325, CVE-2007-3555, CVE-2008-5432, MSA-08-0021, MDL-884 ...