Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

debian логотип

CVE-2011-4591

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the print_object function ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4590

больше 13 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-4590

больше 13 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-4589

больше 13 лет назад

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2011-4589

больше 13 лет назад

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2 ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2011-4588

больше 13 лет назад

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4588

больше 13 лет назад

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4587

больше 13 лет назад

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4587

больше 13 лет назад

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4586

больше 13 лет назад

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-4591

Cross-site scripting (XSS) vulnerability in the print_object function ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4590

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4590

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4589

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4589

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2 ...

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4588

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

CVSS2: 5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4588

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ...

CVSS2: 5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4587

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4587

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ...

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4586

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS2: 5
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться