CVE-2008-3327

NameCVE-2008-3327
DescriptionMoodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
moodlesource(unstable)(unfixed)unimportant

Notes

http://moodle.org/mod/forum/discuss.php?d=101403
Does not allow any attack vectors, apart from gaining non-sensible information

Search for package or bug name: Reporting problems