Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 647
CVE-2011-4287
admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.
CVE-2011-4287
admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force ...
CVE-2011-4286
Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos.
CVE-2011-4286
Multiple cross-site scripting (XSS) vulnerabilities in the media-filte ...
CVE-2011-4285
The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
CVE-2011-4285
The default configuration of Moodle 2.0.x before 2.0.2 has an incorrec ...
CVE-2011-4284
Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.
CVE-2011-4284
Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive ...
CVE-2011-4283
Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml.
CVE-2011-4283
Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterp ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2011-4287 admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user. | CVSS2: 6.8 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4287 admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force ... | CVSS2: 6.8 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4286 Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos. | CVSS2: 4.3 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4286 Multiple cross-site scripting (XSS) vulnerabilities in the media-filte ... | CVSS2: 4.3 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4285 The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role. | CVSS2: 5.5 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4285 The default configuration of Moodle 2.0.x before 2.0.2 has an incorrec ... | CVSS2: 5.5 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4284 Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page. | CVSS2: 5 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4284 Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive ... | CVSS2: 5 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4283 Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml. | CVSS2: 5 | 0% Низкий | больше 13 лет назад | |
CVE-2011-4283 Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterp ... | CVSS2: 5 | 0% Низкий | больше 13 лет назад |
Уязвимостей на страницу