Several remote vulnerabilities have been discovered in Moodle, a
course management system. The Common Vulnerabilities and Exposures
project identifies the following problems:
CVE-2010-1613
Moodle does not enable the "Regenerate session id during
login" setting by default, which makes it easier for remote
attackers to conduct session fixation attacks.
CVE-2010-1614
Multiple cross-site scripting (XSS) vulnerabilities allow
remote attackers to inject arbitrary web script or HTML via
vectors related to (1) the Login-As feature or (2) when the
global search feature is enabled, unspecified global search
forms in the Global Search Engine.
CVE-2010-1615
Multiple SQL injection vulnerabilities allow remote attackers to execute arbitrary SQL commands via vectors related to (1)
the add_to_log function in mod/wiki/view.php in the wiki
module, or (2) "data validation in some forms elements"
related to lib/form/selectgroups.php.
CVE-2010-1616
Moodle can create new roles when restoring a course, which
a...
Get the latest Linux and open source security news straight to your inbox.