Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

ubuntu логотип

CVE-2011-4584

почти 13 лет назад

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4581

почти 13 лет назад

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4585

почти 13 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4583

почти 13 лет назад

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-0801

почти 13 лет назад

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2012-0801

почти 13 лет назад

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 d ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-0800

почти 13 лет назад

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2012-0800

почти 13 лет назад

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2. ...

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2012-0799

почти 13 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0799

почти 13 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous fr ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2011-4584

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4581

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4585

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4583

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0801

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.

CVSS2: 7.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0801

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 d ...

CVSS2: 7.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0800

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0800

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2. ...

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0799

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0799

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous fr ...

CVSS2: 4.3
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться