Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 713

Количество 2 713

debian логотип

CVE-2016-9188

почти 10 лет назад

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-9187

почти 10 лет назад

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-9187

почти 10 лет назад

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-9187

почти 10 лет назад

Unrestricted file upload vulnerability in the double extension support ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-9186

почти 10 лет назад

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-9186

почти 10 лет назад

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-9186

почти 10 лет назад

Unrestricted file upload vulnerability in the "legacy course files" an ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-8644

больше 9 лет назад

In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-8644

больше 9 лет назад

In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-8644

больше 9 лет назад

In Moodle 2.x and 3.x, the capability to view course notes is checked ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-8643

больше 9 лет назад

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-8643

больше 9 лет назад

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-8643

больше 9 лет назад

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit a ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2016-8642

больше 9 лет назад

In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-8642

больше 9 лет назад

In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-8642

больше 9 лет назад

In Moodle 2.x and 3.x, the question engine allows access to files that ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7919

почти 10 лет назад

Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-7919

почти 10 лет назад

Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-7919

почти 10 лет назад

Moodle 3.1.2 allows remote attackers to obtain sensitive information v ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7038

больше 9 лет назад

In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2016-9188

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before ...

CVSS3: 6.1
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support ...

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9186

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-9186

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-9186

Unrestricted file upload vulnerability in the "legacy course files" an ...

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-8644

In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-8644

In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-8644

In Moodle 2.x and 3.x, the capability to view course notes is checked ...

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-8643

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-8643

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-8643

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit a ...

CVSS3: 4.3
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-8642

In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-8642

In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-8642

In Moodle 2.x and 3.x, the question engine allows access to files that ...

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7919

Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.

CVSS3: 7.5
2%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-7919

Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.

CVSS3: 7.5
2%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-7919

Moodle 3.1.2 allows remote attackers to obtain sensitive information v ...

CVSS3: 7.5
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7038

In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

CVSS3: 7.3
1%
Низкий
больше 9 лет назад

Уязвимостей на страницу