CVE-2009-4305
Published: 16 December 2009
SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."
Priority
Status
Package | Release | Status |
---|---|---|
moodle Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
intrepid |
Ignored
(end of life, was needed)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Ignored
(end of life)
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Not vulnerable
(1.9.9.dfsg2-2)
|
|
oneiric |
Not vulnerable
(1.9.9.dfsg2-3)
|
|
precise |
Not vulnerable
(1.9.9.dfsg2-6)
|
|
quantal |
Not vulnerable
(1.9.9.dfsg2-6)
|
|
raring |
Not vulnerable
(1.9.9.dfsg2-6)
|
|
saucy |
Not vulnerable
(1.9.9.dfsg2-6)
|
|
upstream |
Needs triage
|