Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 470

nvd логотип

CVE-2008-1502

около 17 лет назад

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-1502

около 17 лет назад

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-1502

около 17 лет назад

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-6538

больше 17 лет назад

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-6538

больше 17 лет назад

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-6538

больше 17 лет назад

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-3555

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-1502

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

CVSS2: 4.3
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-1502

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in ...

CVSS2: 4.3
1%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-1502

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

CVSS2: 4.3
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8 ...

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2007-6538

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2007-6538

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php ...

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2007-6538

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2007-3555

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
5%
Низкий
почти 18 лет назад

Уязвимостей на страницу


Поделиться