CVE-2013-3630

NameCVE-2013-3630
DescriptionMoodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Notes

For Moodle: Not a securiy issue according to upstream, only applicable to administrators, see bug #775842
https://tracker.moodle.org/browse/MDL-41449
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats

Search for package or bug name: Reporting problems