Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2012-4401

больше 13 лет назад

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-4401

больше 13 лет назад

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authent ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-4400

больше 13 лет назад

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-4400

больше 13 лет назад

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-4408

больше 13 лет назад

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4407

больше 13 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4403

больше 13 лет назад

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4401

больше 13 лет назад

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-4400

больше 13 лет назад

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-4402

больше 13 лет назад

webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-4401

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4401

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authent ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4400

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4400

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4408

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4407

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

CVSS2: 5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4403

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

CVSS2: 5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4401

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4400

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4402

webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

CVSS2: 4.9
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться