Upstream information
CVE-2008-5432 at MITRE
Description
Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).
NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry:
457599
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| openSUSE 10.3 | moodle >= 1.8.2-17.10 moodle-af >= 1.8.2-17.10 moodle-ar >= 1.8.2-17.10 moodle-be >= 1.8.2-17.10 moodle-bg >= 1.8.2-17.10 moodle-bs >= 1.8.2-17.10 moodle-ca >= 1.8.2-17.10 moodle-cs >= 1.8.2-17.10 moodle-da >= 1.8.2-17.10 moodle-de >= 1.8.2-17.10 moodle-de_du >= 1.8.2-17.10 moodle-el >= 1.8.2-17.10 moodle-es >= 1.8.2-17.10 moodle-et >= 1.8.2-17.10 moodle-eu >= 1.8.2-17.10 moodle-fa >= 1.8.2-17.10 moodle-fi >= 1.8.2-17.10 moodle-fr >= 1.8.2-17.10 moodle-ga >= 1.8.2-17.10 moodle-gl >= 1.8.2-17.10 moodle-he >= 1.8.2-17.10 moodle-hi >= 1.8.2-17.10 moodle-hr >= 1.8.2-17.10 moodle-hu >= 1.8.2-17.10 moodle-id >= 1.8.2-17.10 moodle-is >= 1.8.2-17.10 moodle-it >= 1.8.2-17.10 moodle-ja >= 1.8.2-17.10 moodle-ka >= 1.8.2-17.10 moodle-km >= 1.8.2-17.10 moodle-kn >= 1.8.2-17.10 moodle-ko >= 1.8.2-17.10 moodle-lt >= 1.8.2-17.10 moodle-lv >= 1.8.2-17.10 moodle-mi_tn >= 1.8.2-17.10 moodle-ms >= 1.8.2-17.10 moodle-nl >= 1.8.2-17.10 moodle-nn >= 1.8.2-17.10 moodle-no >= 1.8.2-17.10 moodle-pl >= 1.8.2-17.10 moodle-pt >= 1.8.2-17.10 moodle-ro >= 1.8.2-17.10 moodle-ru >= 1.8.2-17.10 moodle-sk >= 1.8.2-17.10 moodle-sl >= 1.8.2-17.10 moodle-so >= 1.8.2-17.10 moodle-sq >= 1.8.2-17.10 moodle-sr >= 1.8.2-17.10 moodle-sv >= 1.8.2-17.10 moodle-th >= 1.8.2-17.10 moodle-tl >= 1.8.2-17.10 moodle-tr >= 1.8.2-17.10 moodle-uk >= 1.8.2-17.10 moodle-vi >= 1.8.2-17.10 moodle-zh_cn >= 1.8.2-17.10
| |