Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2014-0215

около 11 лет назад

The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0215

около 11 лет назад

The blind-marking implementation in Moodle through 2.3.11, 2.4.x befor ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-0214

около 11 лет назад

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-0214

около 11 лет назад

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-0214

около 11 лет назад

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x b ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-0213

около 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-0213

около 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-0213

около 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assi ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-0129

больше 11 лет назад

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-0129

больше 11 лет назад

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0129

больше 11 лет назад

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-0127

больше 11 лет назад

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2014-0127

больше 11 лет назад

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2014-0127

больше 11 лет назад

The time-validation implementation in (1) mod/feedback/complete.php an ...

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2014-0126

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-0126

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-0126

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-0125

больше 11 лет назад

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2014-0125

больше 11 лет назад

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2014-0125

больше 11 лет назад

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4 ...

CVSS2: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-0215

The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.

CVSS2: 4
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-0215

The blind-marking implementation in Moodle through 2.3.11, 2.4.x befor ...

CVSS2: 4
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

CVSS2: 6.8
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x b ...

CVSS2: 6.8
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.

CVSS2: 6.8
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assi ...

CVSS2: 6.8
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-0129

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0129

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

CVSS2: 4
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0129

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6. ...

CVSS2: 4
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0127

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0127

The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0127

The time-validation implementation in (1) mod/feedback/complete.php an ...

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0126

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0126

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0126

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4 ...

CVSS2: 5.8
0%
Низкий
больше 11 лет назад

Уязвимостей на страницу