Candidate: CVE-2012-3395 PublicDate: 2012-07-23 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3395 http://openwall.com/lists/oss-security/2012/07/17/1 Description: SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=682203 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_moodle: upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=9d8d2ee6192e8b7ebb6713bd6215e06f94e2a9f7&st=commit&s=MDL-27675 upstream_moodle: released (2.2.3.dfsg-2.1) hardy_moodle: ignored (reached end-of-life) lucid_moodle: not-affected natty_moodle: not-affected oneiric_moodle: not-affected precise_moodle: not-affected devel_moodle: not-affected (2.2.3.dfsg-2.1)