223 lines
8.0 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2009-0500",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-02-10T02:30:00.530",
"lastModified": "2020-12-01T14:43:53.067",
"vulnStatus": "Modified",
"cveTags": [],
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report."
},
{
"lang": "es",
"value": "Vulnerabilidad de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en el archivo course/lib.php en Moodle v1.6 anteriores a la v1.6.9, v1.7 anteriores a v1.7.7, v1.8 anteriores a v1.8.8, y v1.9 anteriores a v1.9.4, que permite a los atacantes remotos inyectar arbitrariamente una secuencia de comandos web o HTML a trav\u00e9s de una tabla de informaci\u00f3n log manipulada que no est\u00e1 manejada adecuadamente cuando es mostrada en un informe log."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "680CE396-5F61-409C-A152-4D1E1CB44EA3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "C6A0F31A-BB19-4B2C-A2CD-1DFA5FDF1C72"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.2:*:*:*:*:*:*:*",
"matchCriteriaId": "98CA6482-0B84-463D-9C81-A92FFC06C9FA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.3:*:*:*:*:*:*:*",
"matchCriteriaId": "0794B997-0793-4465-B9BA-5BFF254D600A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.4:*:*:*:*:*:*:*",
"matchCriteriaId": "06F4A1D8-65C5-4EDA-BCEC-CD267DE5C4B3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.5:*:*:*:*:*:*:*",
"matchCriteriaId": "AB2A20C9-5FEF-4D91-AFA0-B49672CC8B37"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.6:*:*:*:*:*:*:*",
"matchCriteriaId": "DCFEA024-4CA7-4975-802C-1BB9C099C164"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.7:*:*:*:*:*:*:*",
"matchCriteriaId": "D1E5E19D-BC58-478E-A584-6D260A5C5265"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.6.8:*:*:*:*:*:*:*",
"matchCriteriaId": "CD6C092A-2871-475E-AE53-DC02EB9C3FBD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.7.1:*:*:*:*:*:*:*",
"matchCriteriaId": "FB16198E-A32D-4CFA-9CCE-65871596E6AC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.7.2:*:*:*:*:*:*:*",
"matchCriteriaId": "ABFE9D24-24DB-49EA-B59E-AF9B47D46EB4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.7.3:*:*:*:*:*:*:*",
"matchCriteriaId": "56551145-5213-4165-88C9-C351DACDD1C6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.7.4:*:*:*:*:*:*:*",
"matchCriteriaId": "A589727E-92BB-40DA-8172-89279EB9B73C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.7.5:*:*:*:*:*:*:*",
"matchCriteriaId": "92E97539-A7CC-48D3-A897-ADE4BC194B2E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.7.6:*:*:*:*:*:*:*",
"matchCriteriaId": "D19C1954-6330-449D-9101-378D5DBD122C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.8.1:*:*:*:*:*:*:*",
"matchCriteriaId": "492A28FE-A2F8-4FF7-AC5B-0C3F5508506D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.8.2:*:*:*:*:*:*:*",
"matchCriteriaId": "28A897CA-3D8F-4575-BBD2-1C0C5A2ECC99"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.8.3:*:*:*:*:*:*:*",
"matchCriteriaId": "A4A3A5D9-D96E-46B3-AC22-25045564EB96"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.8.4:*:*:*:*:*:*:*",
"matchCriteriaId": "AF91F8EA-1737-4E11-9931-ACAFB4BC0018"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.8.5:*:*:*:*:*:*:*",
"matchCriteriaId": "1E81E148-5710-439C-8A1A-884D27640AAD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.8.6:*:*:*:*:*:*:*",
"matchCriteriaId": "A3B70465-F734-4C65-9790-0D83D03B7A16"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.8.7:*:*:*:*:*:*:*",
"matchCriteriaId": "DE2C0217-A25A-4D0A-8CC6-64DEBC9E198F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.1:*:*:*:*:*:*:*",
"matchCriteriaId": "24F2602B-8ED3-4026-A9A4-31BE8BDC7724"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.2:*:*:*:*:*:*:*",
"matchCriteriaId": "D7F24649-B67F-4809-9F54-7B623AEF5A4A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.3:*:*:*:*:*:*:*",
"matchCriteriaId": "6B81655E-C3B5-4115-A4C4-B7AC2FCDAB7F"
}
]
}
]
}
],
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html",
"source": "cve@mitre.org"
},
{
"url": "http://moodle.org/security/",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/33955",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/34418",
"source": "cve@mitre.org"
},
2023-04-24 12:24:31 +02:00
{
"url": "http://www.debian.org/security/2009/dsa-1724",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2009/02/04/1",
"source": "cve@mitre.org"
}
]
}