cbcvebase.
CVE-2008-6124
published 2009-02-13

CVE-2008-6124: SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5…

PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.17%
64.3th percentile
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
moodlemoodle>= 1.6 < 1.6.71.6.7
moodlemoodle>= 1.7 < 1.7.51.7.5
moodlemoodle>= 1.8 < 1.8.61.8.6
moodlemoodle>= 1.9 < 1.9.21.9.2

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.