vendor:
Moodle
by:
Antonio 's4tan' Parata, Francesco 'ascii' Ongaro, Giovanni 'evilaliv3' Pellerano
7.3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Moodle
Affected Version From: Moodle 1.9.3
Affected Version To: Moodle 1.9.3
Patch Exists: YES
Related CWE: N/A
CPE: a:moodle:moodle
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Moodle 1.9.3 Remote Code Execution
A Remote Code Execution exists in Moodle 1.9.3. A Remote Code Execution (RCE) vulnerability has been found in filter/tex/texed.php. In order to exploit this vulnerability register_globals must be enabled as the 'TeX Notation' filter. The parameter '$pathname' is not sanitized and can be used to inject arbitrary commands.
Mitigation:
Upgrade to Moodle 1.9.4 or later.