Lucene search

K
cvelistMitreCVELIST:CVE-2006-4943
HistorySep 23, 2006 - 12:00 a.m.

CVE-2006-4943

2006-09-2300:00:00
mitre
www.cve.org
3
moodle
vulnerability
session key
remote attackers
sensitive information

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

61.1%

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

61.1%

Related for CVELIST:CVE-2006-4943