Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2008-3327
Moodle 1.6.5 when display_errors is enabled allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php which reveals the installation path in an error message.