Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 535

debian логотип

CVE-2009-4304

больше 15 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random pa ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-4303

больше 15 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4303

больше 15 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hash ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-4302

больше 15 лет назад

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4302

больше 15 лет назад

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-4301

больше 15 лет назад

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2009-4301

больше 15 лет назад

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MN ...

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2009-4300

больше 15 лет назад

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4300

больше 15 лет назад

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.1 ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-4299

больше 15 лет назад

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2009-4304

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random pa ...

CVSS2: 7.5
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4303

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

CVSS2: 5
1%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4303

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hash ...

CVSS2: 5
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4302

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

CVSS2: 5
1%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4302

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 ...

CVSS2: 5
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4301

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.

CVSS2: 6
1%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4301

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MN ...

CVSS2: 6
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4300

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4300

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.1 ...

CVSS2: 5
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4299

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.

CVSS2: 5
1%
Низкий
больше 15 лет назад

Уязвимостей на страницу


Поделиться