Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 535

debian логотип

CVE-2011-4300

около 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4299

около 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4299

около 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4298

около 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4298

около 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4305

около 13 лет назад

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4307

около 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4300

около 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4309

около 13 лет назад

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4303

около 13 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
0%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
0%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki ...

CVSS2: 6.8
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2011-4305

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

CVSS2: 4
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2011-4307

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

CVSS2: 4.3
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2011-4309

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

CVSS2: 5
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2011-4303

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

CVSS2: 4.3
0%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться