Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
CVE-2012-4407
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ...
CVE-2012-4403
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.
CVE-2012-4403
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly con ...
CVE-2012-4402
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.
CVE-2012-4402
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, a ...
CVE-2012-4401
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
CVE-2012-4401
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authent ...
CVE-2012-4400
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
CVE-2012-4400
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x ...
CVE-2012-4402
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2012-4407 lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ... | CVSS2: 5 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4403 theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response. | CVSS2: 5 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4403 theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly con ... | CVSS2: 5 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4402 webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service. | CVSS2: 4.9 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4402 webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, a ... | CVSS2: 4.9 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4401 Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities. | CVSS2: 4 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4401 Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authent ... | CVSS2: 4 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4400 repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field. | CVSS2: 4 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4400 repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x ... | CVSS2: 4 | 1% Низкий | почти 14 лет назад | |
CVE-2012-4402 webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service. | CVSS2: 4.9 | 1% Низкий | почти 14 лет назад |
Уязвимостей на страницу