Description
help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.
Remediation
References
Related Vulnerabilities
WordPress Plugin Button Widget Smartsoft Cross-Site Request Forgery (1.0.1)
MySQL CVE-2017-10165 Vulnerability (CVE-2017-10165)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Cross-Site Request Forgery (4.2.3)
WordPress Plugin aoringo LOG maker Cross-Site Scripting (0.1.3)
WordPress Plugin Booking Ultra Pro Appointments Booking Calendar Local File Inclusion (1.1.13)