moodle has an insecure temp file vulnerability. From the
Red Hat Bug entry:
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite
arbitrary files via a symlink attack on the
/tmp/spell-check-debug.log, /tmp/spell-check-before, or
/tmp/spell-check-after temporary file.