Количество 2 470
Количество 2 470
CVE-2012-5473
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ...

CVE-2012-5472
lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

CVE-2012-5472
lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.
CVE-2012-5472
lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 a ...

CVE-2012-5471
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

CVE-2012-5471
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.
CVE-2012-5471
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x ...

CVE-2012-4408
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

CVE-2012-4408
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.
CVE-2012-4408
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ...

CVE-2012-4407
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

CVE-2012-4407
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
CVE-2012-4407
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ...

CVE-2012-4403
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

CVE-2012-4403
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.
CVE-2012-4403
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly con ...

CVE-2012-4402
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

CVE-2012-4402
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.
CVE-2012-4402
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, a ...

CVE-2012-4401
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2012-5473 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ... | CVSS2: 4 | 0% Низкий | больше 12 лет назад | |
![]() | CVE-2012-5472 lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field. | CVSS2: 4 | 0% Низкий | больше 12 лет назад |
![]() | CVE-2012-5472 lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field. | CVSS2: 4 | 0% Низкий | больше 12 лет назад |
CVE-2012-5472 lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 a ... | CVSS2: 4 | 0% Низкий | больше 12 лет назад | |
![]() | CVE-2012-5471 The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout. | CVSS2: 6.5 | 0% Низкий | больше 12 лет назад |
![]() | CVE-2012-5471 The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout. | CVSS2: 6.5 | 0% Низкий | больше 12 лет назад |
CVE-2012-5471 The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x ... | CVSS2: 6.5 | 0% Низкий | больше 12 лет назад | |
![]() | CVE-2012-4408 course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation. | CVSS2: 5.5 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-4408 course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation. | CVSS2: 5.5 | 0% Низкий | почти 13 лет назад |
CVE-2012-4408 course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ... | CVSS2: 5.5 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-4407 lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file. | CVSS2: 5 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-4407 lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file. | CVSS2: 5 | 0% Низкий | почти 13 лет назад |
CVE-2012-4407 lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ... | CVSS2: 5 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-4403 theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response. | CVSS2: 5 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-4403 theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response. | CVSS2: 5 | 0% Низкий | почти 13 лет назад |
CVE-2012-4403 theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly con ... | CVSS2: 5 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-4402 webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service. | CVSS2: 4.9 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-4402 webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service. | CVSS2: 4.9 | 0% Низкий | почти 13 лет назад |
CVE-2012-4402 webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, a ... | CVSS2: 4.9 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-4401 Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities. | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
Уязвимостей на страницу