Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.14.24.34.44.55.02022202320242025202620272028

Недавние уязвимости Moodle

Количество 2 469

debian логотип

CVE-2006-6625

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in M ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2006-6625

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2006-6626

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2006-5219

больше 18 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2006-5219

больше 18 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Mo ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2006-5219

больше 18 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-4939

больше 18 лет назад

backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-4936

больше 18 лет назад

Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2006-4935

больше 18 лет назад

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2006-4937

больше 18 лет назад

lib/setup.php in Moodle before 1.6.2 sets the error reporting level to 7 to display E_WARNING messages to users even if debugging is disabled, which might allow remote authenticated users to obtain sensitive information by triggering the messages.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2006-6625

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in M ...

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-6625

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-6626

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-5219

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
2%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-5219

SQL injection vulnerability in blog/index.php in the blog module in Mo ...

CVSS2: 5.1
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-5219

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
2%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-4939

backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.

CVSS2: 5
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-4936

Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.

CVSS2: 10
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-4935

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

CVSS2: 10
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-4937

lib/setup.php in Moodle before 1.6.2 sets the error reporting level to 7 to display E_WARNING messages to users even if debugging is disabled, which might allow remote authenticated users to obtain sensitive information by triggering the messages.

CVSS2: 4
0%
Низкий
больше 18 лет назад

Уязвимостей на страницу


Поделиться