Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2012-0799

около 14 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous fr ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0798

около 14 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-0798

около 14 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2. ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-0797

около 14 лет назад

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-0797

около 14 лет назад

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x befo ...

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-0796

около 14 лет назад

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-0796

около 14 лет назад

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-0795

около 14 лет назад

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-0795

около 14 лет назад

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, an ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-0794

около 14 лет назад

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-0799

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous fr ...

CVSS2: 4.3
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

CVSS2: 5.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2. ...

CVSS2: 5.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-0797

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

CVSS2: 5.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2012-0797

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x befo ...

CVSS2: 5.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-0796

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

CVSS2: 4
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-0796

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x ...

CVSS2: 4
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

CVSS2: 6.5
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, an ...

CVSS2: 6.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-0794

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

CVSS2: 5
1%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться