Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-5337

Опубликовано: 22 фев. 2016
Источник: debian
EPSS Низкий

Описание

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodlefixed2.7.11+dfsg-1package
moodleend-of-lifesqueezepackage

EPSS

Процентиль: 55%
0.00329
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 9 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.

CVSS3: 6.1
nvd
больше 9 лет назад

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.

CVSS3: 6.1
github
около 3 лет назад

Moodle XSS Vulnerability

fstec
больше 9 лет назад

Уязвимость системы управления обучением Мoodle, позволяющая нарушителю провести XSS-атаки

EPSS

Процентиль: 55%
0.00329
Низкий