Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

debian логотип

CVE-2012-6087

больше 12 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11 ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-5674

больше 12 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6087

больше 12 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-4313

больше 12 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4341

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4942

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4942

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the U ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4941

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4941

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Upload ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4940

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11 ...

CVSS2: 5.8
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-4341

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
8%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4942

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4942

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the U ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4941

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4941

Cross-site scripting (XSS) vulnerability in uploader.swf in the Upload ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4940

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться