Description
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery by BestWebSoft 'php.php' Arbitrary File Upload (3.06)
WordPress Plugin NextGEN Gallery-WordPress Gallery Security Bypass (3.1.6)
Joomla! Core 3.x.x Local File Inclusion (3.0.0 - 3.9.25)
Jboss EAP CVE-2013-1896 Vulnerability (CVE-2013-1896)
Internet Information Services Other Vulnerability (CVE-2002-1908)