peter bassill · operator
$ cve CVE-2007-1647 JSON

CVE-2007-1647 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS3.34% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2007-03-24
Last modified2026-06-16

Affected (1)

VendorProduct
moodlemoodle

Public exploits

SourceTitleDate
exploit-dbMoodle 1.5.2 - 'moodledata' Remote Session Disclosure2007-03-18

References

→ the Explorer  ·  watch your stack  ·  NVD