Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

redhat логотип

CVE-2008-5153

почти 17 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

EPSS: Низкий
nvd логотип

CVE-2008-3325

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2008-3326

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-3327

почти 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3325

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before ...

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2008-3327

почти 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3326

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1. ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2008-3325

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2008-3326

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2008-1502

около 17 лет назад

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3327

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before ...

CVSS2: 6
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3327

Moodle 1.6.5, when display_errors is enabled, allows remote attackers ...

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1. ...

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
redhat логотип
CVE-2008-1502

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

1%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться