Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-3326
HistoryJul 25, 2008 - 12:00 a.m.

CVE-2008-3326

2008-07-2500:00:00
ubuntu.com
ubuntu.com
17

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.009

Percentile

83.0%

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x
before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject
arbitrary web script or HTML via the etitle parameter (blog entry title).

Bugs

Notes

Author Note
jdstrand PoC at http://www.procheckup.com/Vulnerability_PR08-13.php reassigned priority to medium due to location of the vulnerability and the ease of exploitation for a non-privileged user (needs only blog access)

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.009

Percentile

83.0%