CVE

Id
9853  
CVE No.
CVE-2004-1425  
Status
Candidate  
Description
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.  
Phase
Assigned (20050212)  
Votes
None (candidate not yet proposed)  
Comments