Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2013-4341

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through ...

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2013-5674

почти 13 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly han ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-4313

почти 13 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-4313

почти 13 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5 ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-6087

почти 13 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2012-6087

почти 13 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11 ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-4341

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2013-5674

почти 13 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6087

почти 13 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-4313

почти 13 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-4341

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through ...

CVSS2: 4.3
22%
Средний
почти 13 лет назад
debian логотип
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly han ...

CVSS2: 7.5
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5 ...

CVSS2: 7.5
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11 ...

CVSS2: 5.8
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-4341

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
22%
Средний
почти 13 лет назад
ubuntu логотип
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
1%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться