SecurityAlert : 1614 CVE : CVE-2006-4896 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Available : No Credit : Omid (omid hackers ir) Published : 22.09.2006
Affected Software :
Moodle 1.6.1+ (and maybe
before versions)
Advisory Content :
Hi,
There is a sql injection in Moodle 1.6.1+ (and maybe
before versions) :
The "$blogEntry" parameter passed to "insert_record()"
function in /blog/edit.php, is not checked properly .
Version 1.6.2 has been released (moodle.org).
- Omid
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.