Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-4298
HistoryDec 16, 2009 - 12:00 a.m.

CVE-2009-4298

2009-12-1600:00:00
ubuntu.com
ubuntu.com
14

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.006

Percentile

78.3%

The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before
1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields
within the user table, which allows attackers to obtain user account
information via unknown vectors.

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.006

Percentile

78.3%