Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-0796 | First vendor Publication | 2012-07-17 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0796 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:15119 | |||
Oval ID: | oval:org.mitre.oval:def:15119 | ||
Title: | DSA-2421-1 moodle -- several | ||
Description: | Several security issues have been fixed in Moodle, a course management system for online learning: CVE-2011-4308 / CVE-2012-0792 Rossiani Wijaya discovered an information leak in mod/forum/user.php CVE-2011-4584 MNET authentication didn't prevent a user using "Login As" from jumping to a remove MNET SSO. CVE-2011-4585 Darragh Enright discovered that the change password form was send in over plain HTTP even if httpslogin was set to "true". CVE-2011-4586 David Michael Evans and German Sanchez Gances discovered CRLF injection/HTTP response splitting vulnerabilities in the Calendar module. CVE-2011-4587 Stephen Mc Guiness discovered empty passwords could be entered in some circumstances. CVE-2011-4588 Patrick McNeill that IP address restrictions could be bypassed in MNET. CVE-2012-0796 Simon Coggins discovered that additional information could be injected into mail headers. CVE-2012-0795 John Ehringer discovered that email adresses were insufficiently validated. CVE-2012-0794 Rajesh Taneja discovered that cookie encryption used a fixed key. CVE-2012-0793 Eloy Lafuente discovered that profile images were insufficiently protected. A new configuration option "forceloginforprofileimages" was introduced for that. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2421-1 CVE-2011-4308 CVE-2011-4584 CVE-2011-4585 CVE-2011-4586 CVE-2011-4587 CVE-2011-4588 CVE-2012-0792 CVE-2012-0793 CVE-2012-0794 CVE-2012-0795 CVE-2012-0796 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | moodle |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-04-02 | Name : Fedora Update for moodle FEDORA-2012-0913 File : nvt/gb_fedora_2012_0913_moodle_fc16.nasl |
2012-03-12 | Name : Debian Security Advisory DSA 2421-1 (moodle) File : nvt/deb_2421_1.nasl |
2012-02-03 | Name : Fedora Update for moodle FEDORA-2012-0939 File : nvt/gb_fedora_2012_0939_moodle_fc15.nasl |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-03-01 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2421.nasl - Type : ACT_GATHER_INFO |
2012-02-03 | Name : The remote Fedora host is missing a security update. File : fedora_2012-0913.nasl - Type : ACT_GATHER_INFO |
2012-02-03 | Name : The remote Fedora host is missing a security update. File : fedora_2012-0939.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:01:07 |
|
2024-11-28 12:28:55 |
|
2023-02-13 09:28:41 |
|
2021-05-04 12:19:18 |
|
2021-04-22 01:23:02 |
|
2020-12-01 17:22:47 |
|
2020-05-23 00:32:59 |
|
2017-12-22 09:21:05 |
|
2016-04-26 21:33:14 |
|
2014-02-17 11:08:19 |
|
2013-05-10 22:33:52 |
|