CVE-2007-1647
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows...
- Published
- Mar 24, 2007
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Mar 18, 2007
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:N/A:NLow · next 30 days
- Percentile
- 88.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.
Sources
1xSh · php · Mar 18, 2007
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.