CVE-2005-3648 Information

Description

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

Reference

http://marc.info/?l=bugtraq&m=113165668814241&w=2 http://osvdb.org/20748 http://rgod.altervista.org/moodle16dev.html http://secunia.com/advisories/17526/ http://securitytracker.com/id?1015181 http://www.securityfocus.com/bid/15380/ http://www.vupen.com/english/advisories/2005/2387 https://exchange.xforce.ibmcloud.com/vulnerabilities/23058

Share on: