CVE-2005-3648

Publication date 17 November 2005

Last updated 24 July 2024


Ubuntu priority

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

Read the notes from the security team

Status

Package Ubuntu Release Status
moodle 7.10 gutsy
Fixed 1.8.2-1
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

1.5.2 and earlier