Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

debian логотип

CVE-2015-2269

около 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript- ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-2268

около 10 лет назад

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2268

около 10 лет назад

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2268

около 10 лет назад

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6. ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-2267

около 10 лет назад

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-2267

около 10 лет назад

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-2267

около 10 лет назад

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-2266

около 10 лет назад

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-2266

около 10 лет назад

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-2266

около 10 лет назад

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x b ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-1493

около 10 лет назад

Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading PHP scripts.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-1493

около 10 лет назад

Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading PHP scripts.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-1493

около 10 лет назад

Directory traversal vulnerability in the min_get_slash_argument functi ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0218

около 10 лет назад

Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-0218

около 10 лет назад

Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0218

около 10 лет назад

Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/log ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0217

около 10 лет назад

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-0217

около 10 лет назад

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0217

около 10 лет назад

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2. ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0216

около 10 лет назад

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2015-2269

Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript- ...

CVSS2: 3.5
1%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-2268

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-2268

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
1%
Низкий
около 10 лет назад
debian логотип
CVE-2015-2268

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6. ...

CVSS2: 6.8
1%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-2267

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-2267

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-2267

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-2266

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-2266

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-2266

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x b ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-1493

Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading PHP scripts.

CVSS2: 6.8
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-1493

Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading PHP scripts.

CVSS2: 6.8
1%
Низкий
около 10 лет назад
debian логотип
CVE-2015-1493

Directory traversal vulnerability in the min_get_slash_argument functi ...

CVSS2: 6.8
1%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0218

Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

CVSS2: 6.8
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0218

Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

CVSS2: 6.8
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0218

Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/log ...

CVSS2: 6.8
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0217

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-0217

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression.

CVSS2: 6.8
1%
Низкий
около 10 лет назад
debian логотип
CVE-2015-0217

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2. ...

CVSS2: 6.8
1%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-0216

access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVSS2: 3.5
0%
Низкий
около 10 лет назад

Уязвимостей на страницу