Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

ubuntu логотип

CVE-2014-9059

больше 10 лет назад

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9059

больше 10 лет назад

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9059

больше 10 лет назад

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x befo ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-7848

больше 10 лет назад

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-7848

больше 10 лет назад

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-7848

больше 10 лет назад

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-7847

больше 10 лет назад

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitude for an IP address.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-7847

больше 10 лет назад

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitude for an IP address.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-7847

больше 10 лет назад

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-7846

больше 10 лет назад

tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access restrictions via an AJAX request.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-7846

больше 10 лет назад

tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access restrictions via an AJAX request.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-7846

больше 10 лет назад

tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-7845

больше 10 лет назад

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-7845

больше 10 лет назад

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-7845

больше 10 лет назад

The generate_password function in Moodle through 2.4.11, 2.5.x before ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-7838

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-7838

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-7838

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Foru ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-7837

больше 10 лет назад

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2014-7837

больше 10 лет назад

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

CVSS2: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-9059

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9059

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9059

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x befo ...

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7848

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

CVSS2: 5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7848

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

CVSS2: 5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7848

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x befor ...

CVSS2: 5
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7847

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitude for an IP address.

CVSS2: 5
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7847

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitude for an IP address.

CVSS2: 5
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7847

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x ...

CVSS2: 5
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7846

tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access restrictions via an AJAX request.

CVSS2: 4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7846

tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access restrictions via an AJAX request.

CVSS2: 4
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7846

tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, ...

CVSS2: 4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7845

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

CVSS2: 7.5
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7845

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

CVSS2: 7.5
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7845

The generate_password function in Moodle through 2.4.11, 2.5.x before ...

CVSS2: 7.5
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7838

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7838

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-7838

Multiple cross-site request forgery (CSRF) vulnerabilities in the Foru ...

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-7837

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

CVSS2: 5.5
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-7837

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

CVSS2: 5.5
1%
Низкий
больше 10 лет назад

Уязвимостей на страницу