CVE-2010-1618
Published: 29 April 2010
Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.
Notes
Author | Note |
---|---|
kees | MSA-10-0002 http://tracker.moodle.org/browse/MDL-21802 |
Priority
Status
Package | Release | Status |
---|---|---|
moodle Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Ignored
(end of life)
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Not vulnerable
(1.9.9.dfsg2-2)
|
|
oneiric |
Not vulnerable
(1.9.9.dfsg2-2)
|
|
precise |
Not vulnerable
(1.9.9.dfsg2-2)
|
|
quantal |
Not vulnerable
(1.9.9.dfsg2-2)
|
|
raring |
Not vulnerable
(1.9.9.dfsg2-2)
|
|
saucy |
Not vulnerable
(1.9.9.dfsg2-2)
|
|
upstream |
Released
(1.9.8)
|