Количество 2 470
Количество 2 470
CVE-2016-9187
Unrestricted file upload vulnerability in the double extension support ...

CVE-2016-9186
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVE-2016-9186
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
CVE-2016-9186
Unrestricted file upload vulnerability in the "legacy course files" an ...

CVE-2016-8644
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

CVE-2016-8644
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
CVE-2016-8644
In Moodle 2.x and 3.x, the capability to view course notes is checked ...

CVE-2016-8643
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVE-2016-8643
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
CVE-2016-8643
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit a ...

CVE-2016-8642
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

CVE-2016-8642
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
CVE-2016-8642
In Moodle 2.x and 3.x, the question engine allows access to files that ...

CVE-2016-7919
** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."

CVE-2016-7919
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.
CVE-2016-7919
Moodle 3.1.2 allows remote attackers to obtain sensitive information v ...

CVE-2016-7038
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

CVE-2016-7038
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
CVE-2016-7038
In Moodle 2.x and 3.x, web service tokens are not invalidated when the ...

CVE-2016-5014
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2016-9187 Unrestricted file upload vulnerability in the double extension support ... | CVSS3: 8.8 | 4% Низкий | больше 8 лет назад | |
![]() | CVE-2016-9186 Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | CVSS3: 8.8 | 4% Низкий | больше 8 лет назад |
![]() | CVE-2016-9186 Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | CVSS3: 8.8 | 4% Низкий | больше 8 лет назад |
CVE-2016-9186 Unrestricted file upload vulnerability in the "legacy course files" an ... | CVSS3: 8.8 | 4% Низкий | больше 8 лет назад | |
![]() | CVE-2016-8644 In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-8644 In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад |
CVE-2016-8644 In Moodle 2.x and 3.x, the capability to view course notes is checked ... | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-8643 In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-8643 In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад |
CVE-2016-8643 In Moodle 2.x and 3.x, non-admin site managers may accidentally edit a ... | CVSS3: 4.3 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-8642 In Moodle 2.x and 3.x, the question engine allows access to files that should not be available. | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-8642 In Moodle 2.x and 3.x, the question engine allows access to files that should not be available. | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад |
CVE-2016-8642 In Moodle 2.x and 3.x, the question engine allows access to files that ... | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-7919 ** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields." | CVSS3: 7.5 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-7919 Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields. | CVSS3: 7.5 | 0% Низкий | больше 8 лет назад |
CVE-2016-7919 Moodle 3.1.2 allows remote attackers to obtain sensitive information v ... | CVSS3: 7.5 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-7038 In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | CVSS3: 7.3 | 0% Низкий | больше 8 лет назад |
![]() | CVE-2016-7038 In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | CVSS3: 7.3 | 0% Низкий | больше 8 лет назад |
CVE-2016-7038 In Moodle 2.x and 3.x, web service tokens are not invalidated when the ... | CVSS3: 7.3 | 0% Низкий | больше 8 лет назад | |
![]() | CVE-2016-5014 In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | CVSS3: 5.4 | 0% Низкий | больше 8 лет назад |
Уязвимостей на страницу