5

CVE-2012-6112

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

Data is provided by the National Vulnerability Database (NVD)
TinymceSpellchecker Php Version2.0
TinymceSpellchecker Php Version2.0 Updatea1
TinymceSpellchecker Php Version2.0 Updatea2
TinymceSpellchecker Php Version2.0 Updateb1
TinymceSpellchecker Php Version2.0 Updateb2
TinymceSpellchecker Php Version2.0 Updateb3
TinymceSpellchecker Php Version2.0 Updaterc1
TinymceSpellchecker Php Version2.0.1
TinymceSpellchecker Php Version2.0.2
TinymceSpellchecker Php Version2.0.3
TinymceSpellchecker Php Version2.0.6
MoodleMoodle Version2.1.0
MoodleMoodle Version2.1.1
MoodleMoodle Version2.1.2
MoodleMoodle Version2.1.3
MoodleMoodle Version2.1.4
MoodleMoodle Version2.1.5
MoodleMoodle Version2.1.6
MoodleMoodle Version2.1.7
MoodleMoodle Version2.1.8
MoodleMoodle Version2.1.9
MoodleMoodle Version2.2.0
MoodleMoodle Version2.2.1
MoodleMoodle Version2.2.2
MoodleMoodle Version2.2.3
MoodleMoodle Version2.2.4
MoodleMoodle Version2.2.5
MoodleMoodle Version2.2.6
MoodleMoodle Version2.3.0
MoodleMoodle Version2.3.1
MoodleMoodle Version2.3.2
MoodleMoodle Version2.3.3
MoodleMoodle Version2.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.6% 0.669
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N