CVE-2008-0123

Publication date 12 January 2008

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
moodle 8.04 LTS hardy Ignored end of life
7.10 gutsy Ignored end of life
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
moodle