CVE Database
/

CVE-2009-4302

Back to search

CVE-2009-4302

Published: Dec 16, 2009

Modified: Sep 16, 2024

PUBLISHED

Description

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2009-3455
vdb-entry
x_refsource_VUPEN
37614
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-13065
vendor-advisory
x_refsource_FEDORA
FEDORA-2009-13040
vendor-advisory
x_refsource_FEDORA
FEDORA-2009-13080
vendor-advisory
x_refsource_FEDORA
37244
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now