CVE-2008-6124
published 2009-02-13CVE-2008-6124: SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5…
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.17%
64.3th percentile
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| moodle | moodle | >= 1.6 < 1.6.7 | 1.6.7 |
| moodle | moodle | >= 1.7 < 1.7.5 | 1.7.5 |
| moodle | moodle | >= 1.8 < 1.8.6 | 1.8.6 |
| moodle | moodle | >= 1.9 < 1.9.2 | 1.9.2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Moodle vulnerabilities
vendor_ubuntu·2009-06-24·CVSS 6.8
CVE-2009-0500 [MEDIUM] Moodle vulnerabilities
Title: Moodle vulnerabilities
Summary: Moodle vulnerabilities
Thor Larholm discovered that PHPMailer, as used by Moodle, did not
correctly escape email addresses. A local attacker with direct access
to the Moodle database could exploit this to execute arbitrary commands
as the web server user. (CVE-2007-3215)
Nigel McNie discovered that fetching https URLs did not correctly escape
shell meta-characters. An authenticated remote attacker could execute
arbitrary commands as the web server user, if curl was installed and
configured. (CVE-2008-4796, MSA-09-0003)
It was discovered that Smarty (also included in Moodle), did not
correctly filter certain inputs. An authenticated remote attacker could
exploit this to execute arbitrary PHP commands as the web server user.
(CVE-2008-4810, CVE-2008
GHSA
GHSA-m38p-4c43-vjrc: SQL injection vulnerability in the hotpot_delete_selected_attempts function in report
ghsa_unreviewed·2022-05-14
CVE-2008-6124 [HIGH] CWE-89 GHSA-m38p-4c43-vjrc: SQL injection vulnerability in the hotpot_delete_selected_attempts function in report
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://cvs.moodle.org/moodle/mod/hotpot/report.php?r1=1.8.6.1&r2=1.8.6.2http://moodle.org/mod/forum/discuss.php?d=101402http://www.debian.org/security/2008/dsa-1691http://cvs.moodle.org/moodle/mod/hotpot/report.php?r1=1.8.6.1&r2=1.8.6.2http://moodle.org/mod/forum/discuss.php?d=101402http://www.debian.org/security/2008/dsa-1691
2009-02-13
Published