CVE-2009-0500

Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
moodlemoodle
1.6.0
moodlemoodle
1.6.1
moodlemoodle
1.6.2
moodlemoodle
1.6.3
moodlemoodle
1.6.4
moodlemoodle
1.6.5
moodlemoodle
1.6.6
moodlemoodle
1.6.7
moodlemoodle
1.6.8
moodlemoodle
1.7.1
moodlemoodle
1.7.2
moodlemoodle
1.7.3
moodlemoodle
1.7.4
moodlemoodle
1.7.5
moodlemoodle
1.7.6
moodlemoodle
1.8.1
moodlemoodle
1.8.2
moodlemoodle
1.8.3
moodlemoodle
1.8.4
moodlemoodle
1.8.5
moodlemoodle
1.8.6
moodlemoodle
1.8.7
moodlemoodle
1.9.1
moodlemoodle
1.9.2
moodlemoodle
1.9.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
moodle
karmic
not-affected
jaunty
not-affected
intrepid
Fixed 1.8.2-1.2ubuntu2.1
released
hardy
Fixed 1.8.2-1ubuntu4.2
released
gutsy
ignored
dapper
ignored