CVE-2007-1647
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.
Published
2007-03-24T00:19:00.000
Last Modified
2025-04-09T00:30:58.490
Status
Deferred
Source
[email protected]
Severity
CVSSv2: 7.8 (HIGH)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: COMPLETE
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
10.0
Impact Score
6.9
Weaknesses
-
Type: Primary
NVD-CWE-Other
Affected Vendors & Products
| Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
| Application |
moodle
|
moodle
|
≤ 1.5.2 |
Yes
|
References