漏洞信息详情
Moodle HotPot Module 'report.php' SQL注入漏洞
- CNNVD编号:CNNVD-200902-294
- 危害等级: 高危
- CVE编号: CVE-2008-6124
- 漏洞类型: SQL注入
- 发布时间: 2009-02-13
- 威胁类型: 远程
- 更新时间: 2009-02-13
- 厂 商: moodle
- 漏洞来源: Moodle
漏洞简介
Moodle是一个免费的学习管理和进度管理、可以用来建立在线教育网站的工具。
Moodle 1.6.7之前的1.6,1.7.5之前的1.7,1.8.6之前的1.8和1.9.2之前的1.9版本的热保留区中的report.php里的hotpot_delete_selected_attempts函数存在SQL注入漏洞。远程攻击者可以借助一个特制的精选的尝试,执行任意的SQL指令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 4.0 arm
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.2_all.deb
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2ubuntu2.1_all.deb
Debian Linux 4.0 powerpc
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Ubuntu Ubuntu Linux 8.10 i386
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2ubuntu2.1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.2_all.deb
Debian Linux 4.0 m68k
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Moodle moodle 1.6.1 +
Moodle moodle-1.6.9.tgz
http://download.moodle.org/download.php/stable16/moodle-1.6.9.tgz
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.2_all.deb
Moodle moodle 1.9
Moodle moodle-1.9.4.tgz
http://download.moodle.org/download.php/stable19/moodle-1.9.4.tgz
Ubuntu Ubuntu Linux 8.10 lpia
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2ubuntu2.1_all.deb
Debian Linux 4.0 amd64
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Debian Linux 4.0 ia-32
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Debian Linux 4.0 hppa
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Debian Linux 4.0 sparc
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Debian Linux 4.0 s/390
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2ubuntu2.1_all.deb
Debian Linux 4.0 alpha
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Debian Linux 4.0
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.2_all.deb
Debian Linux 4.0 mipsel
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Ubuntu Ubuntu Linux 8.10 amd64
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2ubuntu2.1_all.deb
Debian Linux 4.0 ia-64
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb
Debian Linux 4.0 mips
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+etch2_all.deb"
Moodle moodle-1.6.9.tgz
http://download.moodle.org/download.php/stable16/moodle-1.6.9.tgz
Moodle moodle-1.6.9.tgz
http://download.moodle.org/download.php/stable16/moodle-1.6.9.tgz
参考网址
来源: /moodle.org
链接:http://moodle.org/mod/forum/discuss.php?d=101402
来源: DEBIAN
名称: DSA-1691
链接:http://www.debian.org/security/2008/dsa-1691
来源: MISC
链接:http://cvs.moodle.org/moodle/mod/hotpot/report.php?r1=1.8.6.1&r2=1.8.6.2
受影响实体
- Moodle Moodle:1.6
- Moodle Moodle:1.6.1
- Moodle Moodle:1.6.2
- Moodle Moodle:1.6.3
- Moodle Moodle:1.6.4
补丁
暂无
![weinxin](http://zone.ci/zone_ci_images/zone.ci.png)
评论