VYPR
Unrated severityNVD Advisory· Published Sep 14, 2006· Updated Jun 16, 2026

CVE-2006-4784

CVE-2006-4784

Description

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.

Affected products

2
  • Moodle/Moodle2 versions
    cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*range: <=1.6.1
    • (no CPE)range: <=1.6.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.