Candidate: CVE-2012-4403 PublicDate: 2012-09-19 10:57:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4403 http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-35168 http://openwall.com/lists/oss-security/2012/09/17/1 http://moodle.org/mod/forum/discuss.php?d=211560 Description: theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_moodle: upstream_moodle: released (2.3.2) hardy_moodle: ignored (reached end-of-life) lucid_moodle: not-affected natty_moodle: not-affected oneiric_moodle: not-affected precise_moodle: not-affected devel_moodle: not-affected (2.2.3.dfsg-2.2)