First published: Tue Mar 13 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1429 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-1429, upgrade Moodle to a version that has patched these vulnerabilities.
The potential impacts of CVE-2007-1429 include unauthorized remote code execution and complete system compromise.
CVE-2007-1429 specifically affects Moodle version 1.7.1.
Attackers could exploit CVE-2007-1429 by injecting malicious URLs through the cmd parameter in specific PHP scripts.