Description
SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.
Remediation
References
Related Vulnerabilities
Atlassian Jira Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-39127)
Vanilla Forums Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000432)
TYPO3 Other Vulnerability (CVE-2006-0327)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-1831)