Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.05.12022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 541

redhat логотип

CVE-2010-1617

больше 15 лет назад

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

EPSS: Низкий
redhat логотип

CVE-2010-1618

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.

EPSS: Низкий
redhat логотип

CVE-2010-1616

больше 15 лет назад

Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capability.

EPSS: Низкий
nvd логотип

CVE-2009-4305

почти 16 лет назад

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2009-4305

почти 16 лет назад

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1 ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2009-4304

почти 16 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-4304

почти 16 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random pa ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-4303

почти 16 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4303

почти 16 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hash ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-4302

почти 16 лет назад

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2010-1617

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-1618

Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.

0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-1616

Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capability.

0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4305

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

CVSS2: 6.5
1%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-4305

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1 ...

CVSS2: 6.5
1%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-4304

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-4304

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random pa ...

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-4303

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

CVSS2: 5
1%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-4303

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hash ...

CVSS2: 5
1%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-4302

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

CVSS2: 5
1%
Низкий
почти 16 лет назад

Уязвимостей на страницу


Поделиться