UBUNTU-CVE-2013-4313

Source
https://ubuntu.com/security/CVE-2013-4313
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-4313.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-4313
Upstream
  • CVE-2013-4313
Withdrawn
2025-07-18T16:42:55Z
Published
2013-09-16T13:02:00Z
Modified
2025-07-16T07:31:21.024662Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

References

Affected packages

Ubuntu:14.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle@2.5.4-1ubuntu1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.4-1ubuntu1

Affected versions

2.*
2.5.2-1
2.5.3-1
2.5.3-2
2.5.3-3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.5.4-1ubuntu1",
            "binary_name": "moodle"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-4313.json"