CVE-2009-4301

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.
References
Link Resource
http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.16.2.10&r2=1.16.2.11 Patch
http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.9.2.7&r2=1.9.2.8 Patch
http://docs.moodle.org/en/Moodle_1.8.11_release_notes Patch
http://docs.moodle.org/en/Moodle_1.9.7_release_notes Patch
http://moodle.org/mod/forum/discuss.php?d=139106 Patch Vendor Advisory
http://secunia.com/advisories/37614 Vendor Advisory
http://www.securityfocus.com/bid/37244 Patch
http://www.vupen.com/english/advisories/2009/3455 Vendor Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html
http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.16.2.10&r2=1.16.2.11 Patch
http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.9.2.7&r2=1.9.2.8 Patch
http://docs.moodle.org/en/Moodle_1.8.11_release_notes Patch
http://docs.moodle.org/en/Moodle_1.9.7_release_notes Patch
http://moodle.org/mod/forum/discuss.php?d=139106 Patch Vendor Advisory
http://secunia.com/advisories/37614 Vendor Advisory
http://www.securityfocus.com/bid/37244 Patch
http://www.vupen.com/english/advisories/2009/3455 Vendor Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.7:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.8:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.9:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.8.10:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.9.5:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:1.9.6:*:*:*:*:*:*:*

History

21 Nov 2024, 01:09

Type Values Removed Values Added
References () http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.16.2.10&r2=1.16.2.11 - Patch () http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.16.2.10&r2=1.16.2.11 - Patch
References () http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.9.2.7&r2=1.9.2.8 - Patch () http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.9.2.7&r2=1.9.2.8 - Patch
References () http://docs.moodle.org/en/Moodle_1.8.11_release_notes - Patch () http://docs.moodle.org/en/Moodle_1.8.11_release_notes - Patch
References () http://docs.moodle.org/en/Moodle_1.9.7_release_notes - Patch () http://docs.moodle.org/en/Moodle_1.9.7_release_notes - Patch
References () http://moodle.org/mod/forum/discuss.php?d=139106 - Patch, Vendor Advisory () http://moodle.org/mod/forum/discuss.php?d=139106 - Patch, Vendor Advisory
References () http://secunia.com/advisories/37614 - Vendor Advisory () http://secunia.com/advisories/37614 - Vendor Advisory
References () http://www.securityfocus.com/bid/37244 - Patch () http://www.securityfocus.com/bid/37244 - Patch
References () http://www.vupen.com/english/advisories/2009/3455 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/3455 - Vendor Advisory
References () https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html - () https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html - () https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html - () https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html -

Information

Published : 2009-12-16 01:30

Updated : 2024-11-21 01:09


NVD link : CVE-2009-4301

Mitre link : CVE-2009-4301

CVE.ORG link : CVE-2009-4301


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-264

Permissions, Privileges, and Access Controls