CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
82.9%
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.
secunia.com/advisories/25929
securityreason.com/securityalert/2857
securityvulns.ru/Rdocument391.html
tracker.moodle.org/browse/MDL-10341
tracker.moodle.org/secure/IssueNavigator.jspa?mode=hide&requestId=10252
websecurity.com.ua/1045/
www.debian.org/security/2008/dsa-1691
www.osvdb.org/36366
www.securityfocus.com/archive/1/472727/100/0/threaded
www.securityfocus.com/bid/24748
www.securitytracker.com/id?1018333
exchange.xforce.ibmcloud.com/vulnerabilities/35239