Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 535

debian логотип

CVE-2011-4588

около 13 лет назад

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4587

около 13 лет назад

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4587

около 13 лет назад

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4586

около 13 лет назад

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4586

около 13 лет назад

CRLF injection vulnerability in calendar/set.php in the Calendar subsy ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4585

около 13 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4585

около 13 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use h ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4584

около 13 лет назад

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-4584

около 13 лет назад

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2 ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-4583

около 13 лет назад

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

CVSS2: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-4588

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ...

CVSS2: 5
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4587

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

CVSS2: 6.8
1%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4587

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ...

CVSS2: 6.8
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4586

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS2: 5
0%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4586

CRLF injection vulnerability in calendar/set.php in the Calendar subsy ...

CVSS2: 5
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4585

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
0%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4585

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use h ...

CVSS2: 5
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4584

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

CVSS2: 4
0%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4584

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2 ...

CVSS2: 4
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4583

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

CVSS2: 6.5
0%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться