Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

nvd логотип

CVE-2012-3395

почти 13 лет назад

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-3395

почти 13 лет назад

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0 ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-3394

почти 13 лет назад

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3394

почти 13 лет назад

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x bef ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3393

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-3393

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in repository/lib.php in Mood ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-3392

почти 13 лет назад

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-3392

почти 13 лет назад

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x be ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-3391

почти 13 лет назад

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-3391

почти 13 лет назад

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2 ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0 ...

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x bef ...

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3393

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3393

Cross-site scripting (XSS) vulnerability in repository/lib.php in Mood ...

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3392

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3392

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x be ...

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3391

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3391

mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2 ...

CVSS2: 4
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться