Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
CVE-2011-4591
Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.
CVE-2011-4591
Cross-site scripting (XSS) vulnerability in the print_object function ...
CVE-2011-4590
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
CVE-2011-4590
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x ...
CVE-2011-4589
backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.
CVE-2011-4589
backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2 ...
CVE-2011-4588
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.
CVE-2011-4588
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ...
CVE-2011-4587
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
CVE-2011-4587
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2011-4591 Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states. | CVSS2: 4.3 | 2% Низкий | около 14 лет назад | |
CVE-2011-4591 Cross-site scripting (XSS) vulnerability in the print_object function ... | CVSS2: 4.3 | 2% Низкий | около 14 лет назад | |
CVE-2011-4590 The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server. | CVSS2: 4 | 1% Низкий | около 14 лет назад | |
CVE-2011-4590 The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x ... | CVSS2: 4 | 1% Низкий | около 14 лет назад | |
CVE-2011-4589 backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action. | CVSS2: 5.5 | 1% Низкий | около 14 лет назад | |
CVE-2011-4589 backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2 ... | CVSS2: 5.5 | 1% Низкий | около 14 лет назад | |
CVE-2011-4588 The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request. | CVSS2: 5 | 2% Низкий | около 14 лет назад | |
CVE-2011-4588 The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x befor ... | CVSS2: 5 | 2% Низкий | около 14 лет назад | |
CVE-2011-4587 lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords. | CVSS2: 6.8 | 2% Низкий | около 14 лет назад | |
CVE-2011-4587 lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, a ... | CVSS2: 6.8 | 2% Низкий | около 14 лет назад |
Уязвимостей на страницу