Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2152

Опубликовано: 22 мая 2016
Источник: debian
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodlefixed2.7.13+dfsg-1package

EPSS

Процентиль: 49%
0.00255
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.

CVSS3: 6.1
nvd
больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.

CVSS3: 6.1
github
больше 3 лет назад

Moodle XSS from profile fields from external db

EPSS

Процентиль: 49%
0.00255
Низкий