Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16684
http://marc.info/?l=bugtraq&m=108973588000027&w=2
http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/help.php