CVE-2012-2362 - Interorbital Technology
Description
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18 when Internet Explorer is used allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.
Reference
http://git.moodle.org/gw?p=moodle.git;a=commit;h=038131c8b5614f18c14d964dc53b6960ae6c30d8 http://openwall.com/lists/oss-security/2012/05/23/2 http://osvdb.org/82069 https://moodle.org/mod/forum/discuss.php?d=203052