<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Moodle Security</title>
    <link>http://moodle.org/mod/forum/view.php?f=996</link>
    <description>
&lt;div style=&quot;text-align: left;&quot;&gt; &lt;span class=&quot;nolink&quot;&gt;
  &lt;h2&gt;Moodle Security Procedures&lt;/h2&gt;We treat security issues in Moodle software very seriously. Even though we dedicate a lot of time designing our code to avoid such problems, it is inevitable in a project of this size that new vulnerabilities will occasionally be discovered.&lt;br /&gt;&lt;br /&gt;We welcome reports of security issues and will work with reporters to fix problems and publicise patches to Moodle users as quickly as possible.&lt;br /&gt;
  &lt;h3&gt;How can I report a security issue?&lt;/h3&gt;
  &lt;div style=&quot;margin-left: 40px;&quot;&gt;Please &amp;quot;Create a new issue&amp;quot; in the Moodle Tracker describing the problem (and solution if possible) in detail. Make sure you set the &lt;span style=&quot;font-weight: bold;&quot;&gt;Security Level &lt;/span&gt;accurately to make sure that the security team sees it. Bugs classified as a &amp;quot;Serious security issue&amp;quot; will be hidden from the general public until the security team (led by Petr Skoda) is able to resolve it and publish fixes to registered Moodle sites (see below).&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;
  &lt;h3&gt;How can I keep my site secure?&lt;/h3&gt;
  &lt;ol&gt;
    &lt;li&gt;The usual way is to update your whole Moodle to the latest stable release of the version you are using. It is very safe to go from 1.8.1 to 1.8.2+, for example, at any time. CVS is a very easy way to do this.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
    &lt;li&gt;Many of the notices will include patch information. If you are fairly confident with editing scripts, then it may be easier for you to just patch the affected file.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
  &lt;/ol&gt;
  &lt;h3&gt;How can I keep track of recent security issues?&lt;/h3&gt; &lt;/span&gt;&lt;span class=&quot;nolink&quot;&gt;
  &lt;ol&gt;
    &lt;li&gt;&lt;span class=&quot;nolink&quot;&gt;Register your Moodle sites with moodle.org (visit admin/index.php in your installation to see the registration button), making sure to enable the option of being notified about security issues and updates. After your registration is accepted, your email address will be automatically added to our low-volume securityalerts mailing list.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;
    &lt;li&gt;&lt;span class=&quot;nolink&quot;&gt;&lt;/span&gt;Eventually, all important security issues are published to the general public via the forum on this page. You can subscribe to the RSS feed on this page to automatically add new issues in your favourite feed reader or portal. (Please note that security alerts prior to 2008 were made on a different site and do not appear here.)&lt;br /&gt;&lt;/li&gt;
  &lt;/ol&gt;
  &lt;h3&gt;See also&lt;/h3&gt;
  &lt;ul&gt;
    &lt;li&gt;Security documentation&lt;/li&gt;
    &lt;li&gt;Security FAQ&lt;/li&gt;
  &lt;/ul&gt;&lt;/span&gt;&lt;/div&gt;</description>
    <generator>Moodle</generator>
    <copyright>&amp;#169; 2008 moodle</copyright>
    <image>
      <url>http://moodle.org/pix/i/rsssitelogo.gif</url>
      <title>moodle</title>
      <link>http://moodle.org</link>
      <width>140</width>
      <height>35</height>
    </image>
    <item>
      <category>MSA-08-0018: customised PhpMyAdmin package upgraded to 2.11.8.1</category>
      <title>MSA-08-0018: customised PhpMyAdmin package upgraded to 2.11.8.1</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=102261&amp;parent=451602</link>
      <pubDate>Tue, 29 Jul 2008 19:56:52 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;customised PhpMyAdmin upgraded to 2.11.8.1
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;all
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;upstream - &lt;a target=&quot;_blank&quot; href=&quot;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-6&quot;&gt;PMASA-2008-6&lt;/a&gt;&lt;br /&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15872&quot; target=&quot;newpage&quot;&gt;MDL-15872&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;Install latest package from &lt;a title=&quot;mysql admin&quot; href=&quot;http://moodle.org/mod/data/view.php?d=13&amp;rid=448&quot;&gt;http://moodle.org/mod/data/view.php?d=13&amp;amp;rid=448&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;Added protection against cross-frame scripting. Please note that the XSS problem in setup.php does not affect Moodle because this file is not included in the customised Moodle package.&lt;br /&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=102261&amp;parent=451602</guid>
    </item>
    <item>
      <category>MSA-08-0017: customised PhpMyAdmin upgraded to 2.11.7.1</category>
      <title>MSA-08-0017: customised PhpMyAdmin upgraded to 2.11.7.1</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101413&amp;parent=447882</link>
      <pubDate>Wed, 16 Jul 2008 15:21:22 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;customised PhpMyAdmin upgraded to 2.11.7.1
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;all
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;upstream&lt;br /&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15665&quot; target=&quot;newpage&quot;&gt;MDL-15665&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;Install latest package from &lt;a title=&quot;mysql admin&quot; href=&quot;http://moodle.org/mod/data/view.php?d=13&amp;rid=448&quot;&gt;http://moodle.org/mod/data/view.php?d=13&amp;amp;rid=448&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;A bug that allows XSRF/CSRF by manipulating the db, convcharset and collation_connection parameters was discovered in PhpMyAdmin and fixed there (thanks to YGN Ethical Hacker Group. Details not disclosed yet).  Our local optional add-on based on phpmyadmin has now also been updated with this fix.&lt;br /&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101413&amp;parent=447882</guid>
    </item>
    <item>
      <category>MSA-08-0016: Email could be changed in profile without confirmation </category>
      <title>MSA-08-0016: Email could be changed in profile without confirmation </title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101409&amp;parent=447872</link>
      <pubDate>Wed, 16 Jul 2008 14:29:34 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;&lt;a class=&quot;data autolink&quot; title=&quot;eMail&quot; href=&quot;http://moodle.org/mod/data/view.php?d=13&amp;amp;rid=701&quot; &gt;Email&lt;/a&gt; could be changed in profile without confirmation
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;&amp;lt; 1.8.6, &amp;lt;1.9.2
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;multiple external reports
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-13811&quot; target=&quot;newpage&quot;&gt;MDL-13811&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;upgrade to 1.9.2 or 1.8.6. Patch is provided at &lt;a title=&quot;Add a confirmation step when a user changes their own email address in their profile.&quot; href=&quot;http://tracker.moodle.org/browse/MDL-13811&quot;&gt;&lt;strike&gt;MDL-13811&lt;/strike&gt;&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;In previous versions of Moodle, a user who is already authenticated could change their own email address without having to prove they could access that new email account. In Moodle 1.8.6 and 1.9.2 a new setting called emailchangeconfirmation (default: on) now forces all users on the site to go through a confirmation process whenever they want to change their email account. Moodle 1.6.x and 1.7.x sites have not had this new feature added yet - we highly recommend upgrading to 1.9.x if this concerns you.&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101409&amp;parent=447872</guid>
    </item>
    <item>
      <category>MSA-08-0015: accessible profiles of deleted users </category>
      <title>MSA-08-0015: accessible profiles of deleted users </title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101407&amp;parent=447870</link>
      <pubDate>Wed, 16 Jul 2008 14:25:35 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;accessible profiles of deleted users
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;&amp;lt;1.6.7, &amp;lt;1.7.5, &amp;lt;1.8.6, &amp;lt;1.9.2
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Debbie McDonald and Mauno Korpelainen
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15516&quot; target=&quot;newpage&quot;&gt;MDL-15516&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;upgrade to 1.6.7, 1.7.5, 1.8.6, 1.9.2 or any recent nightly or use patch &lt;a href=&quot;http://cvs.moodle.org/moodle/user/view.php?r1=1.123.2.8&amp;r2=1.123.2.9&quot;&gt;http://cvs.moodle.org/moodle/user/view.php?r1=1.123.2.8&amp;amp;r2=1.123.2.9&lt;/a&gt; &lt;a href=&quot;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;r2=1.38.6.2&quot;&gt;&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;Profiles of deleted users were accessible which allowed spammers to abuse user profiles on some sites. Also please make sure that you have &amp;quot;Force users to login for profiles&amp;quot; set as enabled in admin settings if your site allows registering of new users.&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101407&amp;parent=447870</guid>
    </item>
    <item>
      <category>MSA-08-0014: potential sql injection in events handling code </category>
      <title>MSA-08-0014: potential sql injection in events handling code </title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101406&amp;parent=447868</link>
      <pubDate>Wed, 16 Jul 2008 14:22:14 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;potential sql injection in events handling code
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Minor
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;1.9.0 and 1.9.1 only
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;internal
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15552&quot; target=&quot;newpage&quot;&gt;MDL-15552&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;upgrade to 1.9.2 or any recent nightly; upgrade needed only if custom code uses Events API &lt;a href=&quot;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;r2=1.38.6.2&quot;&gt;&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;During internal review it was discovered that the new Events framework might be vulnerable to sql attacks. This code is not currently used within Moodle core, but sites 3rd party modifications could be vulnerable. If you have any code using Events API please read the details in &lt;a href=&quot;http://tracker.moodle.org/browse/MDL-9983&quot;&gt;http://tracker.moodle.org/browse/MDL-9983&lt;/a&gt; on how to update your code to comply with this change. Please note that the changes in 1.9.2 are not backwards compatible. &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101406&amp;parent=447868</guid>
    </item>
    <item>
      <category> MSA-08-0013: CSRF (Cross-site Request Forgery) on Moodle edit profile page </category>
      <title> MSA-08-0013: CSRF (Cross-site Request Forgery) on Moodle edit profile page </title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101405&amp;parent=447867</link>
      <pubDate>Wed, 16 Jul 2008 14:20:11 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;CSRF (Cross-site Request Forgery) on Moodle edit profile page
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;&amp;lt;1.6.7, &amp;lt;1.7.5
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Amir Azam and Adrian Pastor of ProCheckUp Ltd. (&lt;a href=&quot;http://www.procheckup.com/&quot;&gt;www.procheckup.com)&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15450&quot; target=&quot;newpage&quot;&gt;MDL-15450&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;upgrade to 1.6.7, 1.7.5 or any recent nightly or use patch &lt;a href=&quot;http://cvs.moodle.org/moodle/user/edit.php?r1=1.112.2.4.2.1&amp;r2=1.112.2.4.2.2&quot;&gt;http://cvs.moodle.org/moodle/user/edit.php?r1=1.112.2.4.2.1&amp;amp;r2=1.112.2.4.2.2&lt;/a&gt; + &lt;a href=&quot;http://cvs.moodle.org/moodle/user/Attic/edit.html?r1=1.88.2.3&amp;r2=1.88.2.3.2.1&quot;&gt;http://cvs.moodle.org/moodle/user/Attic/edit.html?r1=1.88.2.3&amp;amp;r2=1.88.2.3.2.1&lt;/a&gt; &lt;a href=&quot;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;r2=1.38.6.2&quot;&gt;&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt; ProCheckup discovered that user profile page in 1.6.x and 1.7.x sites are vulnerable to CSRF (Cross-site Request Forgery) attacks. Versions 1.8 and above are not vulnerable due to to increased protection the forms library enforces. We would like to thank them for informing us in a responsible manner and coordinating the disclosure of security advisories.&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101405&amp;parent=447867</guid>
    </item>
    <item>
      <category>MSA-08-0012: Potential non-persistent XSS when searching for group members (MSSQL and Oracle only) </category>
      <title>MSA-08-0012: Potential non-persistent XSS when searching for group members (MSSQL and Oracle only) </title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101404&amp;parent=447866</link>
      <pubDate>Wed, 16 Jul 2008 14:18:16 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Potential non-persistent XSS when searching for group members (MSSQL and Oracle only)
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;1.9.0, 1.9.1
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;internal
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15079&quot; target=&quot;newpage&quot;&gt;MDL-15079&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;upgrade to 1.9.2 or any recent nightly or use patch &lt;a href=&quot;http://cvs.moodle.org/moodle/group/members.php?r1=1.3.2.4&amp;r2=1.3.2.5&quot;&gt;http://cvs.moodle.org/moodle/group/members.php?r1=1.3.2.4&amp;amp;r2=1.3.2.5&lt;/a&gt; &lt;a href=&quot;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;r2=1.38.6.2&quot;&gt;&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;We have discovered that systems running on MSSQL or Oracle databases are vulnerable to non-persistent cross-site scripting (XSS) attack. This vulnerability was caused by incorrect escaping when using database engines which require sybase style quoting (MSSQL and Orcale Only).&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101404&amp;parent=447866</guid>
    </item>
    <item>
      <category>MSA-08-0011: Potential webroot disclosures warning </category>
      <title>MSA-08-0011: Potential webroot disclosures warning </title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101403&amp;parent=447864</link>
      <pubDate>Wed, 16 Jul 2008 14:15:49 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Potential webroot disclosures warning
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Minor
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;all version
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Richard Brain of ProCheckUp Ltd. (&lt;a href=&quot;http://www.procheckup.com/&quot;&gt;www.procheckup.com&lt;/a&gt;)
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15413&quot; target=&quot;newpage&quot;&gt;MDL-15413&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;make sure display_errors is disabled in PHP configuration; 1.8.6 and 1.9.2 contains new warning for administrators &lt;a href=&quot;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;r2=1.38.6.2&quot;&gt;&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;ProCheckup discovered that several scripts display errors if display_errors enabled in PHP configuration. This problem will be fully fixed in later Moodle versions because it requires modification of many files and review of all code from upstream, in the meantime please make sure you server is configured properly - see &lt;a href=&quot;http://www.php.net/manual/en/errorfunc.configuration.php#ini.display-errors&quot;&gt;http://www.php.net/manual/en/errorfunc.configuration.php#ini.display-errors&lt;/a&gt; &lt;br /&gt; &lt;br /&gt; We would like to thank them for informing us in a responsible manner and coordinating the disclosure of security advisories. &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101403&amp;parent=447864</guid>
    </item>
    <item>
      <category> MSA-08-0010: sql injection in HotPot module</category>
      <title> MSA-08-0010: sql injection in HotPot module</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101402&amp;parent=447863</link>
      <pubDate>Wed, 16 Jul 2008 14:13:02 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;sql injection in &lt;a class=&quot;data autolink&quot; title=&quot;HotPot&quot; href=&quot;http://moodle.org/mod/data/view.php?d=13&amp;amp;rid=91&quot; &gt;HotPot&lt;/a&gt; module
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;&amp;lt;1.6.7, &amp;lt;1.7.5, &amp;lt;1.8.6, &amp;lt;1.9.2
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;internal
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15184&quot; target=&quot;newpage&quot;&gt;MDL-15184&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;upgrade to 1.6.7, 1.7.5, 1.8.6, 1.9.2 or any recent nightly or use patch &lt;a href=&quot;http://cvs.moodle.org/moodle/mod/hotpot/report.php?r1=1.8.6.1&amp;r2=1.8.6.2&quot;&gt;http://cvs.moodle.org/moodle/mod/hotpot/report.php?r1=1.8.6.1&amp;amp;r2=1.8.6.2&lt;/a&gt; &lt;a href=&quot;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;r2=1.38.6.2&quot;&gt;&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;We have discovered that Hotpot module code in report.php was vulnerable to sql injection attacks. &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101402&amp;parent=447863</guid>
    </item>
    <item>
      <category>MSA-08-0009: Persistent Cross-site Scripting (XSS) on blog entry title parameter</category>
      <title>MSA-08-0009: Persistent Cross-site Scripting (XSS) on blog entry title parameter</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=101401&amp;parent=447862</link>
      <pubDate>Wed, 16 Jul 2008 14:10:16 WST</pubDate>
      <description>by Petr Škoda (škoďák). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Persistent Cross-site Scripting (XSS) on blog entry title parameter
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt;&amp;lt;1.6.7, &amp;lt;1.7.5
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Adrian Pastor and Amir Azam of ProCheckUp Ltd. (&lt;a href=&quot;http://www.procheckup.com/&quot;&gt;www.procheckup.com&lt;/a&gt;)
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-15392&quot; target=&quot;newpage&quot;&gt;MDL-15392&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt;upgrade to 1.6.7, 1.7.5 or any recent nightly or use patch &lt;a href=&quot;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;r2=1.38.6.2&quot;&gt;http://cvs.moodle.org/moodle/blog/lib.php?r1=1.38.6.3&amp;amp;r2=1.38.6.2&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;/p&gt;ProCheckup discovered that 1.6.x and 1.7.x sites with enabled blogs are vulnerable to persistent Cross-site Scripting (XSS) attacks through blog entry titles. We would like to thank them for informing us in a responsible manner and coordinating the disclosure of security advisories.&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=101401&amp;parent=447862</guid>
    </item>
  </channel>
</rss>