Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

debian логотип

CVE-2011-4303

больше 13 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4302

больше 13 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4302

больше 13 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x be ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4301

больше 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4301

больше 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4300

больше 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4300

больше 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4299

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4299

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4298

больше 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-4303

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x be ...

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in ...

CVSS2: 5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться