Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 535

Количество 2 535

nvd логотип

CVE-2014-3543

около 11 лет назад

mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via a package with a manifest file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue affecting IMSCP resources and the IMSCC format.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-3543

около 11 лет назад

mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-3542

около 11 лет назад

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-3542

около 11 лет назад

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-3542

около 11 лет назад

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-3541

около 11 лет назад

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-3541

около 11 лет назад

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-3541

около 11 лет назад

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4. ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-2572

больше 11 лет назад

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-2572

больше 11 лет назад

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-2572

больше 11 лет назад

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not prope ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-2571

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2014-2571

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-2571

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-0218

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0218

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-0218

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the URL downloader reposit ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-0217

около 11 лет назад

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-0217

около 11 лет назад

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-0217

около 11 лет назад

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the mo ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-3543

mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via a package with a manifest file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue affecting IMSCP resources and the IMSCC format.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-3543

mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-3542

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-3542

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-3542

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5 ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVSS2: 7.5
2%
Низкий
около 11 лет назад
debian логотип
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4. ...

CVSS2: 7.5
2%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-2572

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

CVSS2: 4
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-2572

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

CVSS2: 4
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-2572

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not prope ...

CVSS2: 4
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-2571

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-2571

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-2571

Cross-site scripting (XSS) vulnerability in the quiz_question_tostring ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0218

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-0218

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-0218

Cross-site scripting (XSS) vulnerability in the URL downloader reposit ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-0217

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-0217

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-0217

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the mo ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад

Уязвимостей на страницу