Lucene search

K
cveMitreCVE-2006-4942
HistorySep 23, 2006 - 12:07 a.m.

CVE-2006-4942

2006-09-2300:07:00
mitre
web.nvd.nist.gov
24
moodle
cve-2006-4942
security vulnerability
remote code execution

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

58.7%

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.

Affected configurations

Nvd
Node
moodlemoodleRange1.6.1
OR
moodlemoodleMatch1.6.0
VendorProductVersionCPE
moodlemoodle*cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
moodlemoodle1.6.0cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

58.7%

Related for CVE-2006-4942