Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

ubuntu логотип

CVE-2007-6538

больше 18 лет назад

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-3555

около 19 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-3555

около 19 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3555

около 19 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1647

больше 19 лет назад

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-1647

больше 19 лет назад

Moodle 1.5.2 and earlier stores sensitive information under the web ro ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1647

больше 19 лет назад

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-1429

больше 19 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-1429

больше 19 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 all ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-1429

больше 19 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2007-6538

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
4%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-3555

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3555

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 ...

CVSS2: 4.3
3%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-3555

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-1647

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1647

Moodle 1.5.2 and earlier stores sensitive information under the web ro ...

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1647

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 all ...

CVSS2: 7.5
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
1%
Низкий
больше 19 лет назад

Уязвимостей на страницу


Поделиться