Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2012-3398

больше 13 лет назад

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-3398

больше 13 лет назад

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2. ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-3397

больше 13 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-3397

больше 13 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-3396

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-3396

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Mo ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-3395

больше 13 лет назад

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-3395

больше 13 лет назад

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0 ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-3394

больше 13 лет назад

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3394

больше 13 лет назад

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x bef ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-3398

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

CVSS2: 4
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3398

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2. ...

CVSS2: 4
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3397

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3397

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3396

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3396

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Mo ...

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0 ...

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x bef ...

CVSS2: 5
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться