Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2015-3272

больше 9 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2015-3272

больше 9 лет назад

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2015-3181

около 10 лет назад

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-3181

около 10 лет назад

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-3181

около 10 лет назад

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-3180

около 10 лет назад

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-3180

около 10 лет назад

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-3180

около 10 лет назад

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-3179

около 10 лет назад

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3179

около 10 лет назад

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3179

около 10 лет назад

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-3178

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3178

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3178

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the external_format_text f ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-3177

около 10 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-3177

около 10 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-3177

около 10 лет назад

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-3176

около 10 лет назад

The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3176

около 10 лет назад

The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3176

около 10 лет назад

The account-confirmation feature in login/confirm.php in Moodle throug ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an HTTP Referer header that has a substring match with a local URL.

CVSS3: 7.4
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlel ...

CVSS3: 7.4
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-3181

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3181

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-file upload, which allows remote authenticated users to bypass intended file-management restrictions by using web services to perform uploads after this capability has been revoked.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3181

files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-3180

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3180

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3180

lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2. ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-3179

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3179

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3179

login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x ...

CVSS2: 3.5
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3178

Cross-site scripting (XSS) vulnerability in the external_format_text f ...

CVSS2: 3.5
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-3177

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3177

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3177

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe ...

CVSS2: 3.5
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-3176

The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.

CVSS2: 4.3
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3176

The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.

CVSS2: 4.3
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3176

The account-confirmation feature in login/confirm.php in Moodle throug ...

CVSS2: 4.3
0%
Низкий
около 10 лет назад

Уязвимостей на страницу