Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-1493
Description:Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading PHP scripts.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2015.0057  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-1493
http://openwall.com/lists/oss-security/2015/02/04/15
http://openwall.com/lists/oss-security/2015/02/09/2




© 1998-2025 E-Soft Inc. All rights reserved.