Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 535
CVE-2011-4588
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ...

CVE-2011-4587
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
CVE-2011-4587
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ...

CVE-2011-4586
CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CVE-2011-4586
CRLF injection vulnerability in calendar/set.php in the Calendar subsy ...

CVE-2011-4585
login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.
CVE-2011-4585
login/change_password.php in Moodle 1.9.x before 1.9.15 does not use h ...

CVE-2011-4584
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
CVE-2011-4584
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2 ...

CVE-2011-4583
Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2011-4588 The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ... | CVSS2: 5 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2011-4587 lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords. | CVSS2: 6.8 | 1% Низкий | около 13 лет назад |
CVE-2011-4587 lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ... | CVSS2: 6.8 | 1% Низкий | около 13 лет назад | |
![]() | CVE-2011-4586 CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | CVSS2: 5 | 0% Низкий | около 13 лет назад |
CVE-2011-4586 CRLF injection vulnerability in calendar/set.php in the Calendar subsy ... | CVSS2: 5 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2011-4585 login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network. | CVSS2: 5 | 0% Низкий | около 13 лет назад |
CVE-2011-4585 login/change_password.php in Moodle 1.9.x before 1.9.15 does not use h ... | CVSS2: 5 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2011-4584 The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site. | CVSS2: 4 | 0% Низкий | около 13 лет назад |
CVE-2011-4584 The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2 ... | CVSS2: 4 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2011-4583 Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens. | CVSS2: 6.5 | 0% Низкий | около 13 лет назад |
Уязвимостей на страницу