CVE-2008-1502
Publication date 25 March 2008
Last updated 24 July 2024
Ubuntu priority
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.
Status
Package | Ubuntu Release | Status |
---|---|---|
egroupware | ||
moodle | ||
Patch details
Package | Patch details |
---|---|
moodle |
References
Related Ubuntu Security Notices (USN)
- USN-658-1
- Moodle vulnerability
- 23 October 2008