Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

debian логотип

CVE-2013-5674

почти 12 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly han ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4938

почти 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4938

почти 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4938

почти 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-4525

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-4525

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4525

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/ ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4524

больше 11 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-4524

больше 11 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-4524

больше 11 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-4523

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-4523

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4523

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4522

больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-4522

больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-4522

больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x b ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2013-4341

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2013-4341

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2013-4341

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2013-4313

почти 12 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly han ...

CVSS2: 7.5
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10 ...

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-4525

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4525

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4525

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/ ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4524

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4524

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4524

Directory traversal vulnerability in repository/filesystem/lib.php in ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4523

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4523

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4523

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x b ...

CVSS2: 5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4341

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
13%
Средний
почти 12 лет назад
nvd логотип
CVE-2013-4341

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

CVSS2: 4.3
13%
Средний
почти 12 лет назад
debian логотип
CVE-2013-4341

Multiple cross-site scripting (XSS) vulnerabilities in Moodle through ...

CVSS2: 4.3
13%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
0%
Низкий
почти 12 лет назад

Уязвимостей на страницу