Lucene search

K
cveMitreCVE-2006-4938
HistorySep 23, 2006 - 12:07 a.m.

CVE-2006-4938

2006-09-2300:07:00
mitre
web.nvd.nist.gov
32
cve-2006-4938
moodle
help.php
security vulnerability
remote authenticated users
error message

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

46.7%

help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

Affected configurations

Nvd
Node
moodlemoodleRange1.6.1
OR
moodlemoodleMatch1.6.0
VendorProductVersionCPE
moodlemoodle*cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
moodlemoodle1.6.0cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

46.7%

Related for CVE-2006-4938