CVE-2008-6124: SQL Injection
SQL injection vulnerability in the hotpotdeleteselectedattempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6124?
CVE-2008-6124 is classified as a medium-severity SQL injection vulnerability that could allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2008-6124?
To fix CVE-2008-6124, it is recommended to upgrade Moodle to version 1.6.7, 1.7.5, 1.8.6, 1.9.2, or later, which contain patches for this vulnerability.
What versions of Moodle are affected by CVE-2008-6124?
CVE-2008-6124 affects Moodle versions prior to 1.6.7, 1.7.5, 1.8.6, and 1.9.2.
Can CVE-2008-6124 be exploited remotely?
Yes, CVE-2008-6124 can be exploited remotely by attackers sending specially crafted requests to the affected Moodle systems.
What are the potential impacts of exploiting CVE-2008-6124?
Exploiting CVE-2008-6124 can lead to unauthorized access to the database, data manipulation, and potentially devastating impacts on the Moodle application.