Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2013-4313

почти 12 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-4313

почти 12 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-3630

больше 11 лет назад

Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

CVSS2: 4.6
EPSS: Средний
nvd логотип

CVE-2013-3630

больше 11 лет назад

Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

CVSS2: 4.6
EPSS: Средний
debian логотип

CVE-2013-3630

больше 11 лет назад

Moodle through 2.5.2 allows remote authenticated administrators to exe ...

CVSS2: 4.6
EPSS: Средний
ubuntu логотип

CVE-2013-2246

почти 12 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-2246

почти 12 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-2246

почти 12 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-2245

почти 12 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-2245

почти 12 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-2245

почти 12 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-2244

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2244

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2244

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionli ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2243

почти 12 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-2243

почти 12 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-2243

почти 12 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x befo ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-2242

почти 12 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-2242

почти 12 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-2242

почти 12 лет назад

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

CVSS2: 7.5
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-4313

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5 ...

CVSS2: 7.5
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-3630

Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

CVSS2: 4.6
64%
Средний
больше 11 лет назад
nvd логотип
CVE-2013-3630

Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

CVSS2: 4.6
64%
Средний
больше 11 лет назад
debian логотип
CVE-2013-3630

Moodle through 2.5.2 allows remote authenticated administrators to exe ...

CVSS2: 4.6
64%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2013-2246

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-2246

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

CVSS2: 4
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-2246

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2. ...

CVSS2: 4
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-2245

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

CVSS2: 4
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-2245

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

CVSS2: 4
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-2245

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo ...

CVSS2: 4
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-2244

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-2244

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-2244

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionli ...

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-2243

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

CVSS2: 4
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-2243

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

CVSS2: 4
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-2243

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x befo ...

CVSS2: 4
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-2242

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

CVSS2: 4
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-2242

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.

CVSS2: 4
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-2242

mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before ...

CVSS2: 4
0%
Низкий
почти 12 лет назад

Уязвимостей на страницу