Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 535

Количество 2 535

nvd логотип

CVE-2014-0008

больше 11 лет назад

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-0008

больше 11 лет назад

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x b ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-5674

почти 12 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-5674

почти 12 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-5674

почти 12 лет назад

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly han ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4938

около 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4938

около 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4938

около 12 лет назад

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-4525

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-4525

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4525

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/ ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4524

больше 11 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-4524

больше 11 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-4524

больше 11 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-4523

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-4523

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-4523

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-4522

больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-4522

больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-4522

больше 11 лет назад

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x b ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-0008

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.

CVSS2: 4
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-0008

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x b ...

CVSS2: 4
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

CVSS2: 7.5
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly han ...

CVSS2: 7.5
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
debian логотип
CVE-2013-4938

The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10 ...

CVSS2: 4.3
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-4525

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4525

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4525

Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/ ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4524

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4524

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4524

Directory traversal vulnerability in repository/filesystem/lib.php in ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4523

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4523

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4523

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

CVSS2: 5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x b ...

CVSS2: 5
0%
Низкий
больше 11 лет назад

Уязвимостей на страницу