Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 536

Количество 2 536

nvd логотип

CVE-2015-5268

больше 9 лет назад

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5268

больше 9 лет назад

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2. ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5267

больше 9 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-5267

больше 9 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-5267

больше 9 лет назад

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-5266

больше 9 лет назад

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-5266

больше 9 лет назад

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2015-5266

больше 9 лет назад

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle thro ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-5265

больше 9 лет назад

The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-5265

больше 9 лет назад

The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2015-5265

больше 9 лет назад

The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8. ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-5264

больше 9 лет назад

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2015-5264

больше 9 лет назад

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2015-5264

больше 9 лет назад

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-3275

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2015-3275

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2015-3275

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM modul ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-3274

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2015-3274

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2015-3274

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the user_get_user_details ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-5268

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5268

The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2. ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVSS3: 7.5
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ...

CVSS3: 7.5
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5266

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5266

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing during a long-running sync script.

CVSS3: 6.8
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5266

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle thro ...

CVSS3: 6.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5265

The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5265

The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5265

The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8. ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-5264

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-5264

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-5264

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x ...

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-3275

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-3275

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-3275

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM modul ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an external_format_text call in a web service.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу