First published: Sun Jan 27 2013(Updated: )
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tinymce Spellchecker Php | =2.0 | |
Tinymce Spellchecker Php | =2.0-a1 | |
Tinymce Spellchecker Php | =2.0-a2 | |
Tinymce Spellchecker Php | =2.0-b1 | |
Tinymce Spellchecker Php | =2.0-b2 | |
Tinymce Spellchecker Php | =2.0-b3 | |
Tinymce Spellchecker Php | =2.0-rc1 | |
Tinymce Spellchecker Php | =2.0.1 | |
Tinymce Spellchecker Php | =2.0.2 | |
Tinymce Spellchecker Php | =2.0.3 | |
Tinymce Spellchecker Php | =2.0.6 | |
Moodle Moodle | =2.1.0 | |
Moodle Moodle | =2.1.1 | |
Moodle Moodle | =2.1.2 | |
Moodle Moodle | =2.1.3 | |
Moodle Moodle | =2.1.4 | |
Moodle Moodle | =2.1.5 | |
Moodle Moodle | =2.1.6 | |
Moodle Moodle | =2.1.7 | |
Moodle Moodle | =2.1.8 | |
Moodle Moodle | =2.1.9 | |
Moodle Moodle | =2.2.0 | |
Moodle Moodle | =2.2.1 | |
Moodle Moodle | =2.2.2 | |
Moodle Moodle | =2.2.3 | |
Moodle Moodle | =2.2.4 | |
Moodle Moodle | =2.2.5 | |
Moodle Moodle | =2.2.6 | |
Moodle Moodle | =2.3.0 | |
Moodle Moodle | =2.3.1 | |
Moodle Moodle | =2.3.2 | |
Moodle Moodle | =2.3.3 | |
Moodle Moodle | =2.4.0 | |
composer/moodle/moodle | =2.4.0 | 2.4.1 |
composer/moodle/moodle | >=2.3.0<2.3.4 | 2.3.4 |
composer/moodle/moodle | >=2.2.0<2.2.7 | 2.2.7 |
composer/moodle/moodle | >=2.1.0<2.1.10 | 2.1.10 |
=2.0 | ||
=2.0-a1 | ||
=2.0-a2 | ||
=2.0-b1 | ||
=2.0-b2 | ||
=2.0-b3 | ||
=2.0-rc1 | ||
=2.0.1 | ||
=2.0.2 | ||
=2.0.3 | ||
=2.0.6 | ||
=2.1.0 | ||
=2.1.1 | ||
=2.1.2 | ||
=2.1.3 | ||
=2.1.4 | ||
=2.1.5 | ||
=2.1.6 | ||
=2.1.7 | ||
=2.1.8 | ||
=2.1.9 | ||
=2.2.0 | ||
=2.2.1 | ||
=2.2.2 | ||
=2.2.3 | ||
=2.2.4 | ||
=2.2.5 | ||
=2.2.6 | ||
=2.3.0 | ||
=2.3.1 | ||
=2.3.2 | ||
=2.3.3 | ||
=2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.