Loading...
Loading...
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.
March 24, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-1647
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.