Back
CVE-2004-1425
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (10)
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 1.1.1 |
| moodle | moodle | 1.2.0 |
| moodle | moodle | 1.2.1 |
| moodle | moodle | 1.3.0 |
| moodle | moodle | 1.3.1 |
| moodle | moodle | 1.3.2 |
| moodle | moodle | 1.3.3 |
| moodle | moodle | 1.3.4 |
| moodle | moodle | 1.4.1 |
| moodle | moodle | 1.4.2 |
GitHub Security Advisory GHSA-3vcq-64gh-84x2
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers...
References (8)
- http://marc.info/?l=bugtraq&m=110425409614735&w=2
- http://marc.info/?l=bugtraq&m=110444531816566&w=2
- http://www.securityfocus.com/bid/12120 Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18550
- http://marc.info/?l=bugtraq&m=110425409614735&w=2
- http://marc.info/?l=bugtraq&m=110444531816566&w=2
- http://www.securityfocus.com/bid/12120 Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18550
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
1.82%
Top 23% most likely to be exploited
Threat Score
20.5 / 100
Data Sources
NVD
EPSS
GitHub