Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 541
BDU:2017-00179
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю нарушить конфиденциальность информации
BDU:2017-00178
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю нарушить конфиденциальность информации
CVE-2016-9188
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
CVE-2016-9188
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before ...
CVE-2016-9187
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
CVE-2016-9187
Unrestricted file upload vulnerability in the double extension support ...
CVE-2016-9186
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
CVE-2016-9186
Unrestricted file upload vulnerability in the "legacy course files" an ...
CVE-2016-9186
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
CVE-2016-9188
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2017-00179 Уязвимость системы управления обучением Мoodle, позволяющая нарушителю нарушить конфиденциальность информации | CVSS2: 5 | 0% Низкий | почти 9 лет назад | |
BDU:2017-00178 Уязвимость системы управления обучением Мoodle, позволяющая нарушителю нарушить конфиденциальность информации | CVSS2: 4 | 0% Низкий | почти 9 лет назад | |
CVE-2016-9188 Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters. | CVSS3: 6.1 | 0% Низкий | около 9 лет назад | |
CVE-2016-9188 Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before ... | CVSS3: 6.1 | 0% Низкий | около 9 лет назад | |
CVE-2016-9187 Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | CVSS3: 8.8 | 3% Низкий | около 9 лет назад | |
CVE-2016-9187 Unrestricted file upload vulnerability in the double extension support ... | CVSS3: 8.8 | 3% Низкий | около 9 лет назад | |
CVE-2016-9186 Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | CVSS3: 8.8 | 3% Низкий | около 9 лет назад | |
CVE-2016-9186 Unrestricted file upload vulnerability in the "legacy course files" an ... | CVSS3: 8.8 | 3% Низкий | около 9 лет назад | |
CVE-2016-9186 Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | CVSS3: 8.8 | 3% Низкий | около 9 лет назад | |
CVE-2016-9188 Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters. | CVSS3: 6.1 | 0% Низкий | около 9 лет назад |
Уязвимостей на страницу