Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 647
CVE-2012-2365
Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.
CVE-2012-2365
Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, ...
CVE-2012-2364
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.
CVE-2012-2364
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle ...
CVE-2012-2363
SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
CVE-2012-2363
SQL injection vulnerability in calendar/event.php in the calendar impl ...
CVE-2012-2362
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.
CVE-2012-2362
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog i ...
CVE-2012-2361
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.
CVE-2012-2361
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2012-2365 Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php. | CVSS2: 3.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2365 Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, ... | CVSS2: 3.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2364 Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action. | CVSS2: 3.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2364 Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle ... | CVSS2: 3.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2363 SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event. | CVSS2: 6.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2363 SQL injection vulnerability in calendar/event.php in the calendar impl ... | CVSS2: 6.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2362 Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php. | CVSS2: 2.6 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2362 Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog i ... | CVSS2: 2.6 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2361 Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php. | CVSS2: 3.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2361 Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php ... | CVSS2: 3.5 | 0% Низкий | больше 13 лет назад |
Уязвимостей на страницу