Unrated severityNVD Advisory· Published Sep 23, 2006· Updated Jun 16, 2026
CVE-2006-4941
CVE-2006-4941
Description
Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitrary web script or HTML via (1) the choose parameter in files/index.php and (2) the sub parameter in doc/index.php.
Affected products
3Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.