oss-sec mailing list archives

Re: CVE request: moodle xss in < 1.8.5


From: Hanno Böck <hanno () hboeck de>
Date: Tue, 8 Jul 2008 13:21:06 +0200

Am Sonntag 06 Juli 2008 schrieb Nico Golde:
Hi Hanno,

* Hanno Böck <hanno () hboeck de> [2008-07-06 19:04]:
http://docs.moodle.org/en/Release_Notes#Moodle_1.8.5
    *  KSES related XSS security vulnerability fixed

This should be CVE-2008-1502:

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1502
is about egroupware.

I found no cve related to moodle 1.8.4.

-- 
Hanno Böck              Blog:           http://www.hboeck.de/
GPG: 3DBD3B20           Jabber/Mail:    hanno () hboeck de

Attachment: signature.asc
Description: This is a digitally signed message part.


Current thread: